Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007434
sonatype-2025-007434
Malicious Packages - Fri Dec 05 2025 [RCE] [Backdoor]
Published Dec 5, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-191989.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192013.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192027.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192037.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192041.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192053.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192096.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192101.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192115.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192140.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192152.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192153.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192163.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192175.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192183.json
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
elf-stats-aurora-garland-513
1.0.1
npm
elf-stats-caroling-giftbox-184
1.0.0
npm
elf-stats-cocoa-northstar-632
1.0.0
npm
elf-stats-cosy-wishlist-811
1.0.2
npm
elf-stats-evergreen-workbench-462
1.0.0
npm
elf-stats-flickering-lantern-502
1.0.0
npm
elf-stats-flickering-workbench-929
1.0.0
npm
elf-stats-frostbitten-wishlist-794
1.0.0
npm
elf-stats-ginger-bell-819
1.0.0
npm
elf-stats-ginger-ledger-106
1.0.1
npm
elf-stats-joyous-toy-711
1.0.0
npm
elf-stats-merry-sparkler-742
1.0.1
npm
elf-stats-midnight-mitten-226
1.0.0
npm
elf-stats-midnight-wreath-655
1.0.0
npm
elf-stats-midnight-wreath-655
1.0.1
npm
elf-stats-mulled-rocket-415
1.0.0
npm
elf-stats-piney-fireplace-695
1.0.0
npm
elf-stats-rooftop-garland-184
1.0.0
npm
elf-stats-snowdusted-bauble-104
1.0.0
npm
elf-stats-snowdusted-fireplace-396
1.0.0
npm
elf-stats-snowy-cookiejar-589
1.0.0
npm
elf-stats-snuggly-workshop-421
9999.0.2
npm
elf-stats-snuggly-workshop-421
9999.0.3
npm
elf-stats-snuggly-workshop-421
9999.0.5
npm
elf-stats-snuggly-workshop-421
9999.0.6
npm
elf-stats-snuggly-workshop-421
9999.0.7
npm
elf-stats-sparkly-bow-901
1.0.0
npm
elf-stats-sparkly-bow-901
1.1.0
npm
elf-stats-sparkly-bow-901
1.2.0
npm
elf-stats-sparkly-sled-484
1.0.0
npm
elf-stats-sparkly-workbench-689
1.0.0
npm
elf-stats-starlit-rocket-905
1.0.0
npm
elf-stats-storybook-cookiejar-394
1.0.2
npm
elf-stats-sugarplum-workshop-950
1.0.0
npm
elf-stats-tinsel-saddlebag-152
1.0.0
npm
elf-stats-twinkling-sled-276
1.0.0
npm
elf-stats-whimsical-ledger-767
1.0.1
npm
elf-stats-whimsical-pantry-173
1.0.0
1-38 of 38
sonatype-2025-007434 | Components Impacted | Sonatype Guide | Sonatype Guide