Entries about malicious packages not in "MAL-" namespace
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 271
- Forks
- 129
- Avg merge
- 3h 46m
- Merged PRs (30d)
- 4
Description
Hello, and first of all, thanks for all the amazing work you do for the community.
I identified several entries related to malicious PyPI packages that are not in the "MAL-" namespace:
PYSEC-2025-3
PYSEC-2025-4
PYSEC-2025-5
PYSEC-2025-6
PYSEC-2025-7
PYSEC-2025-8
PYSEC-2022-199
PYSEC-2024-152
It is a bit tricky to keep track of this unique type of vulnerability entries (Malicious packages) when they are not in that namespace.
Should these entries have assigned a new "MAL-" ID? Or should a new field be added to the schema indicating this type of risk?
Looking forward you thoughts!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the eight listed PYSEC entries and the existing schema conventions for vulnerability identifiers and metadata. Compare the proposed MAL- namespace with adding a field for malicious-package risk. Done means the project has a decided, documented representation and the affected entries follow it.
Written by the indexing model from the issue text.
Assessment
- Domain
- backend-api-design, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100