MISP / MISP/misp-galaxy

ScalpFox entry in wiper.json is unsourced and collides with a legitimate business name — request source or removal

Open Beginner friendly
#1,237 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
639
Forks
315
Avg merge
1d 10h
Merged PRs (30d)
23

Description

Hello,

The "ScalpFox" entry in clusters/wiper.json (UUID 0bebd2c7-014f-4113-8119-f632122b4ef4)
was added in commit 1e77e57d ("Add missing Wikipedia-listed wipers with first-seen
metadata"). However, unlike other entries from that commit, this one has:

  • no external references,
  • no first-seen date,
  • no mention on the Wikipedia wiper page the commit refers to.

I was unable to find any vendor report (Kaspersky, ESET, CrowdStrike, Microsoft,
Malpedia) describing a wiper named "ScalpFox". As far as I can tell, no such malware
family has ever been publicly documented.

Meanwhile, "ScalpFox" is the name of my legitimate business (scalpfox.com, a cryptocurrency scalping service).
Because misp-galaxy.org ranks highly, this entry now appears
in Google search results and in Google's AI Overview for my brand name, which tells
potential customers that "ScalpFox is a destructive wiper" — causing direct
reputational and financial harm to my business.

Could you please provide a verifiable source for this entry, or remove it if none
exists? Thank you.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect the ScalpFox entry in clusters/wiper.json using UUID 0bebd2c7-014f-4113-8119-f632122b4ef4, then review commit 1e77e57d and the referenced Wikipedia wiper page. Verify whether a vendor or other public source supports the entry; done means adding a verifiable source or removing the entry if none exists.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
64/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.