Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007263
sonatype-2025-007263
Malicious Packages - Tue Nov 25 2025 [Credential Info Stealer]
Published Nov 25, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-190602.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-190607.json
CVSS Score
High
7.1
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
airbnb-blueimp-file-upload
95.6.0
npm
airbnb-blueimp-file-upload
96.8.0
npm
airbnb-luxury-messaging
92.4.0
npm
airbnb-phoenix
93.4.0
npm
airbnb-react-router-legacy
97.1.0
npm
airbnb-react-router-legacy-v3
94.5.0
npm
airbnb-story-constants
1.0.0
npm
airbnb-story-constants
91.3.0
npm
airbnb-vermeer-node
95.6.0
npm
o2-modal
97.1.0
npm
o2-tooltip
97.1.0
npm
wishlist_dropdown
97.1.0
1-12 of 12
sonatype-2025-007263 | Components Impacted | Sonatype Guide | Sonatype Guide