-
Notifications
You must be signed in to change notification settings - Fork 127
Expand file tree
/
Copy pathMAL-2025-2552.json
More file actions
58 lines (58 loc) · 1.61 KB
/
Copy pathMAL-2025-2552.json
File metadata and controls
58 lines (58 loc) · 1.61 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
{
"modified": "2025-03-19T23:55:30Z",
"published": "2025-03-19T23:55:30Z",
"schema_version": "1.5.0",
"id": "MAL-2025-2552",
"summary": "Malicious code in io.github.leetcrunch:scribejava-core (Maven)",
"details": "\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: google-open-source-security (8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26)\nA malicious Maven Java package a typosquatting a legitimate OAuth Maven\npackage. The malicious package collects and exfils OAuth credentials on\nthe 15th day of each month.\n",
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "io.github.leetcrunch:scribejava-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
]
}
],
"references": [
{
"type": "ARTICLE",
"url": "https://socket.dev/blog/malicious-maven-package-exfiltrates-oauth-credentials"
}
],
"credits": [
{
"name": "Socket",
"type": "FINDER"
}
],
"database_specific": {
"malicious-packages-origins": [
{
"import_time": "2025-03-20T00:02:04.794639Z",
"modified_time": "2025-03-19T23:55:30Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26",
"source": "google-open-source-security"
}
]
}
}