Skip to content

arduino-ide-extension marked as malware #3487

Closed
@rhaidiz

Description

@rhaidiz

Hello, this is the Arduino Security Team. We have recently came across an advisory published on GitHub (GHSA-7884-8cw4-qpgx) that is reporting the arduino-ide-extention as containing malware.
The package is part of a bigger project called Arduino IDE 2.x (https://github.com/arduino/arduino-ide) and has never been listed in the npm registry.

We believe this to be a part of an attempt from a threat actor to conduct some kind of dependency confusion on our repo.

We have already contacted NPM to let them know of the issue, we would also appreciated it if you could help us in removing this advisory, thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions