Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007488
sonatype-2025-007488
Malicious Packages - Tue Dec 09 2025 [Credential Info Stealer]
Published Dec 9, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192424.json
CVSS Score
High
7.1
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
baidu-oscp
19.9.1
npm
baidu-oscp
19.9.23
npm
baidu-oscp
19.9.24
npm
baidu-oscp
19.9.25
npm
baidu-oscp
19.9.26
npm
baidu-oscp
19.9.27
npm
baidu-oscp
19.9.28
npm
baidu-oscp
19.9.29
npm
baidu-oscp
19.9.2
npm
baidu-oscp
19.9.30
npm
baidu-oscp
19.9.31
npm
baidu-oscp
19.9.33
npm
baidu-oscp
19.9.34
npm
baidu-tester
0.0.1-security
npm
baidu-tester
1.0.0
npm
baidu-tester
1.0.1
npm
baidu-tester
1.0.2
npm
baidu-tester
1.0.3
npm
baidu-tester
1.0.4
1-19 of 19
sonatype-2025-007488 | Components Impacted | Sonatype Guide | Sonatype Guide