Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007456
sonatype-2025-007456
Malicious Packages - Sat Dec 06 2025 [RCE] [Reverse Shell]
Published Dec 8, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192018.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192191.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192215.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192216.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192218.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192219.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192220.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192223.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192225.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192226.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192232.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192236.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192239.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192249.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192250.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192252.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192261.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192269.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192270.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192273.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192275.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192278.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192281.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192284.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192286.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192332.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192341.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192344.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192471.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192480.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192483.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192486.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192495.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192496.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192504.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192505.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192509.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192515.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192517.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192518.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192520.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192523.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192530.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192539.json
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
elf-stats-aurora-sparkler-752
1.0.0
npm
elf-stats-aurora-toy-659
99.9.10
npm
elf-stats-aurora-toy-659
99.9.11
npm
elf-stats-aurora-toy-659
99.9.12
npm
elf-stats-aurora-toy-659
99.9.9
npm
elf-stats-caroling-hammer-382
0.0.1-security
npm
elf-stats-caroling-hammer-382
1.0.0
npm
elf-stats-caroling-workshop-885
5.4.3
npm
elf-stats-caroling-workshop-885
5.5.3
npm
elf-stats-caroling-workshop-885
5.6.3
npm
elf-stats-caroling-workshop-885
5.7.3
npm
elf-stats-caroling-workshop-885
5.8.3
npm
elf-stats-caroling-workshop-885
5.9.3
npm
elf-stats-caroling-workshop-885
5.9.4
npm
elf-stats-cheery-sleigh-538
1.0.0
npm
elf-stats-cocoa-workshop-459
0.0.1-security
npm
elf-stats-cocoa-workshop-459
1.0.0
npm
elf-stats-cocoa-workshop-459
1.0.1
npm
elf-stats-ember-fireplace-220
1.0.0
npm
elf-stats-ember-nutcracker-423
1.0.0
npm
elf-stats-ember-stockpile-641
1.0.0
npm
elf-stats-evergreen-nightcap-747
1.0.0
npm
elf-stats-evergreen-nightcap-747
1.0.1
npm
elf-stats-evergreen-nightcap-747
1.0.2
npm
elf-stats-evergreen-nightcap-747
1.0.3
npm
elf-stats-evergreen-nightcap-747
1.0.7
npm
elf-stats-evergreen-nightcap-747
1.0.8
npm
elf-stats-evergreen-nightcap-747
1.0.9
npm
elf-stats-evergreen-nightcap-747
1.2.1
npm
elf-stats-evergreen-nightcap-747
1.3.1
npm
elf-stats-evergreen-nightcap-747
1.4.0
npm
elf-stats-evergreen-nightcap-747
2.0.0
npm
elf-stats-evergreen-satchel-868
1.0.0
npm
elf-stats-flickering-lantern-502
1.0.0
npm
elf-stats-flickering-workbench-929
1.0.0
npm
elf-stats-frostbitten-pantry-235
1.0.0
npm
elf-stats-ginger-hollyberry-135
1.0.0
npm
elf-stats-gingersnap-mitten-648
1.0.0
npm
elf-stats-glittering-nutcracker-709
1.0.0
npm
elf-stats-glittering-reindeer-615
1.0.0
npm
elf-stats-jolly-workshop-110
1.0.0
npm
elf-stats-joyous-ribbon-819
1.0.0
npm
elf-stats-merry-cookiejar-139
1.0.0
npm
elf-stats-merry-cookiejar-442
1.0.0
npm
elf-stats-merry-cookiejar-442
1.0.1
npm
elf-stats-merry-cookiejar-511
1.0.0
npm
elf-stats-merry-cookiejar-646
1.0.0
npm
elf-stats-merry-hammer-791
1.0.0
npm
elf-stats-mistletoe-mailbag-834
1.0.0
npm
elf-stats-northbound-bauble-535
1.0.0
1-50 of 84
sonatype-2025-007456 | Components Impacted | Sonatype Guide | Sonatype Guide