Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2025-007497
sonatype-2025-007497
Malicious Packages - Tue Dec 09 2025 [Info Stealer]
Published Dec 10, 2025
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-192439.json
CVSS Score
Medium
5.3
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
@vampirchik147/libxmljs2
0.19.7
npm
@vampirchik147/xml
1.0.0
npm
asdfgh3
0.0.1-security
npm
asdfgh3
0.30.1
npm
asdfgh3
0.30.2
npm
asdfgh3
0.30.3
npm
asdfgh3
0.30.4
npm
asdfgh3
0.30.5
npm
asdfgh3
0.30.6
npm
asdfgh3
0.30.7
npm
asdfgh3
0.30.8
npm
asdfgh3
0.30.9
npm
asdfgh33
0.0.1-security
npm
asdfgh33
0.30.2
npm
stnsxmp
0.30.2
npm
stnsxmp2
0.30.1
npm
stnsxmp3
0.30.1
npm
stnsxmp4
0.30.1
npm
stnsxmp4
0.30.2
npm
stnsxmp5
0.30.1
1-20 of 20
sonatype-2025-007497 | Components Impacted | Sonatype Guide | Sonatype Guide