Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please remove all captivateiq instacnes #700

Open
radical-izak opened this issue Dec 6, 2024 · 1 comment
Open

Please remove all captivateiq instacnes #700

radical-izak opened this issue Dec 6, 2024 · 1 comment

Comments

@radical-izak
Copy link

Please help us remove all captivate instance of npm https://github.com/ossf/malicious-packages/tree/main/osv/malicious/npm/%40captivateiq

all of the listed there were just a test of security purposes, now there are no public captivateiq repos

Please let me know if you need any other information

Thank you

@calebbrown
Copy link
Contributor

Hi @radical-izak.

We have a policy of not removing reports of malicious packages once they have been added.

We will only adjust the reports to be more specific for the versions they apply to, or withdraw them if they were not pointing to malicious packages.

The repo serves as a history of malicious packages that have been published to open source repositories as both a resource to researchers and organizations trying to protect themselves.

Furthermore, the repo does not attempt to judge a package on the intent of the author, only on the package itself and its behavior. This means that packages from both malicious attackers and security researchers are fair game for inclusion.

I hope that helps explain. If there is a specific problem you are trying to solve other than merely removing them from the repo, I'd be happy to discuss it more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants