Launch Week Day 1: Announcing Security Design Review
CRITICAL Maven Malware

Malicious code in io.github.leetcrunch:scribejava-core (Maven)

MAL-2025-2552

Published ยท Modified

Description


__

Source: google-open-source-security (8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26)

A malicious Maven Java package a typosquatting a legitimate OAuth Maven
package. The malicious package collects and exfils OAuth credentials on
the 15th day of each month.

Ready to move

Start Securing

Free, no credit card | First findings in minutes