MAL-2025-46928

    Dashboard / Malicious Package / MAL-2025-46928

    MAL-2025-46928

    Published: 1 Sept 2025Last Modified: 23 Jul 2026Aliases: 
    GHSA-5rjh-7746-6hw3

    Summary: Malicious code in monolith-twirp-git_src_migrator-monolith (RubyGems)

    Details: Source: ossf-package-analysis (060f3ebfeb0862be79294c75a97aaa823e0378ae4ef10ce1910472c923b31dc3) The OpenSSF Package Analysis project identified 'monolith-twirp-git_src_migrator-monolith' @ 1.6.3 (rubygems) as malicious. It is considered malicious because: - The package executes one or more commands associated with malicious behavior.

    References:

    Affected packages

    Package

    Name: monolith-twirp-git_src_migrator-monolith

    Purl: pkg:gem/monolith-twirp-git_src_migrator-monolith

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.6.3