Malicious code in io.github.leetcrunch:scribejava-core (Maven)
Malware
Published
Jul 13, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published to the GitHub Advisory Database
Jul 13, 2026
Reviewed
Jul 13, 2026
Last updated
Jul 21, 2026
-= Per source details. Do not edit below this line.=-
Source: google-open-source-security (8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26)
A malicious Maven Java package a typosquatting a legitimate OAuth Maven
package. The malicious package collects and exfils OAuth credentials on
the 15th day of each month.
References