Closed
Description
Hello, this is the Arduino Security Team. We have recently came across an advisory published on GitHub (GHSA-7884-8cw4-qpgx) that is reporting the arduino-ide-extention
as containing malware.
The package is part of a bigger project called Arduino IDE 2.x (https://github.com/arduino/arduino-ide) and has never been listed in the npm registry.
We believe this to be a part of an attempt from a threat actor to conduct some kind of dependency confusion on our repo.
We have already contacted NPM to let them know of the issue, we would also appreciated it if you could help us in removing this advisory, thanks.
Metadata
Metadata
Assignees
Labels
No labels