Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007437
sonatype-2025-007437
Malicious Packages - Fri Dec 05 2025 [RCE] [Backdoor]
Published Dec 5, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-191987.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-191989.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192013.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192027.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192037.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192041.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192053.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192062.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192096.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192101.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192115.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192140.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192144.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192150.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192152.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192153.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192163.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192175.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192183.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192193.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192767.json
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
elf-stats-aurora-garland-513
1.0.1
npm
elf-stats-caroling-giftbox-184
1.0.0
npm
elf-stats-cocoa-northstar-632
1.0.0
npm
elf-stats-cosy-wishlist-811
1.0.2
npm
elf-stats-evergreen-workbench-462
1.0.0
npm
elf-stats-festive-marshmallow-962
1.0.0
npm
elf-stats-flickering-lantern-502
1.0.0
npm
elf-stats-flickering-workbench-929
1.0.0
npm
elf-stats-frostbitten-wishlist-794
1.0.0
npm
elf-stats-ginger-bell-819
1.0.0
npm
elf-stats-ginger-ledger-106
1.0.1
npm
elf-stats-glittering-wishlist-537
1.0.0
npm
elf-stats-joyous-toy-711
1.0.0
npm
elf-stats-marzipan-cookie-302
1.0.0
npm
elf-stats-merry-sparkler-742
1.0.1
npm
elf-stats-midnight-mitten-226
1.0.0
npm
elf-stats-midnight-wreath-655
1.0.0
npm
elf-stats-midnight-wreath-655
1.0.1
npm
elf-stats-mulled-rocket-415
1.0.0
npm
elf-stats-nutmeg-bauble-217
1.0.0
npm
elf-stats-piney-fireplace-695
1.0.0
npm
elf-stats-rooftop-garland-184
1.0.0
npm
elf-stats-snowdusted-bauble-104
1.0.0
npm
elf-stats-snowdusted-fireplace-396
1.0.0
npm
elf-stats-snowy-cookiejar-589
1.0.0
npm
elf-stats-snuggly-rocket-941
1.0.0
npm
elf-stats-snuggly-workshop-421
9999.0.2
npm
elf-stats-snuggly-workshop-421
9999.0.3
npm
elf-stats-snuggly-workshop-421
9999.0.5
npm
elf-stats-snuggly-workshop-421
9999.0.6
npm
elf-stats-snuggly-workshop-421
9999.0.7
npm
elf-stats-sparkly-bow-901
1.0.0
npm
elf-stats-sparkly-bow-901
1.1.0
npm
elf-stats-sparkly-bow-901
1.2.0
npm
elf-stats-sparkly-sled-484
1.0.0
npm
elf-stats-sparkly-workbench-689
1.0.0
npm
elf-stats-starlit-ribbon-255
1.0.0
npm
elf-stats-starlit-rocket-905
1.0.0
npm
elf-stats-storybook-cookiejar-394
1.0.2
npm
elf-stats-sugarplum-workshop-950
1.0.0
npm
elf-stats-tinsel-saddlebag-152
1.0.0
npm
elf-stats-twinkling-sled-276
1.0.0
npm
elf-stats-whimsical-ledger-767
1.0.1
npm
elf-stats-whimsical-pantry-173
1.0.0
npm
elf-stats-whimsical-snowflake-250
0.0.1-security
npm
elf-stats-whimsical-snowflake-250
1.0.0
npm
elf-stats-whimsical-snowflake-250
1.0.1
npm
elf-stats-whimsical-snowflake-250
1.0.2
npm
elf-stats-whimsical-snowflake-250
1.0.3
npm
elf-stats-whimsical-snowflake-250
1.0.4
1-50 of 52
sonatype-2025-007437 | Components Impacted | Sonatype Guide | Sonatype Guide