Skip to content

[Security Fix] Removed malicious package: colrs@1.0.0#6

Open
doria-bot wants to merge 1 commit into
mainfrom
security/fix-colrs-slopsquat
Open

[Security Fix] Removed malicious package: colrs@1.0.0#6
doria-bot wants to merge 1 commit into
mainfrom
security/fix-colrs-slopsquat

Conversation

@doria-bot

Copy link
Copy Markdown
Member

🚨 Security Remediation: Malicious Package Intercepted

🛡️ Threat Summary

Doria has autonomously blocked the installation of co1ors. This package was flagged as a critical supply chain threat during the install-time static analysis and ML evaluation. It has been removed from the environment to prevent execution.

📊 Detection Metrics

1. ⚙️ Static Analysis (AST Engine)

  • Verdict: Malicious shell execution detected.
  • Details: A critical shell_execution via child_process.exec() was found in the postinstall hook, attempting to execute rm -rf / to recursively delete the root directory.

2. 🧠 Behavioral & Metadata Risk (Model 1)

  • ⚠️ Verdict: High behavioral anomaly detected.
  • Confidence: 85.0%
  • Details: Model 1 detected significant behavioral anomalies, indicating a high probability of malicious intent beyond normal package operations.

3. 🏷️ Nomenclature Risk (Model 2)

  • ⚠️ Verdict: High nomenclature risk identified.
  • Confidence: 97.5%
  • Details: Model 2 identified a very high probability of typosquatting or similar naming convention abuse, strongly suggesting a malicious attempt to mimic a legitimate package.

🤖 Automated Remediation

  • Installation of co1ors blocked.
  • Package removed from local cache and dependency tree.
  • Recommended Action: Please review the safe alternative or correct package naming convention.

@elviscgn elviscgn requested review from AshlyVuba, Mphele and elviscgn June 2, 2026 15:31
@sonarqubecloud

sonarqubecloud Bot commented Jun 2, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants