Skip to content

False Positive Malware Flag on @znan/wabot (GHSA-2jxx-8fv2-h8mj) #9268

Description

@znanx

Hello GitHub Security Team,

I am the author and maintainer of the npm package @znan/wabot and the repository znanx/wabot. My package was recently flagged as malware under GHSA-2jxx-8fv2-h8mj.

I would like to clarify that this is a false positive caused by code obfuscation. I used a tool called JSConfuser to encrypt/obfuscate the JavaScript files in the published npm package, which unfortunately triggered your automated malware scanners (CWE-506).

The original, clean, and un-obfuscated source code is fully transparent and available here on my public repository: https://github.com/znan/wabot

My npm account has also been locked due to this automated flag. Could you please review the source code in my repository and remove the malware advisory flag from my package? I am fully prepared to re-publish the package to npm completely un-obfuscated as soon as my account is restored.

Thank you for your time and help.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions