Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2026-000009
sonatype-2026-000009
Malicious Packages - Mon Jan 05 2026 [Info Stealer/Host Data]
Published Jan 5, 2026
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-180.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-312.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-313.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-336.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-39.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-40.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-41.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-45.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-48.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-49.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-50.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-56.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-57.json
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-75.json
CVSS Score
Medium
5.3
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
@cda-apps/source
0.0.1-security
npm
@cda-apps/source
9.0.0
npm
@crepo/crepo-url-query-mapper
11.11.11
npm
@crepo/crepo-url-query-mapper
11.11.12
npm
@signify/vue-components
0.0.1-security
npm
@signify/vue-components
99.0.0
npm
babel-preset-ibm-cloud-cognitive
12.0.2
npm
blob-internal-security-test-f63eabf7
99.99.99
npm
blobhunter-depconf-poc
0.0.1-security
npm
blobhunter-depconf-poc
1.0.0
pypi
blobhunter-depconf-poc
999.0.0
npm
common-cli-utils
0.0.0
npm
connect-me-icon
999.0.0
npm
d4sp
999.0.0
npm
diskho
999.0.0
npm
dstny
999.0.0
npm
dstny-utils
999.0.0
npm
escaux
999.0.0
npm
eslint-config-sdk
1.1.3
npm
ethos2.0
0.0.1-security
npm
ethos2.0
2.0.0
npm
ethos2.0
7.0.0
npm
faceplate-ui
0.0.1-security
npm
faceplate-ui
9.9.9
npm
identity-emitter
0.1.8
npm
ipvision
999.0.0
npm
ipvision-selfcare
999.0.0
npm
jest-config-ibm-cloud-cognitive
12.0.2
npm
meridix
999.0.0
npm
mitel
999.0.0
npm
react-router-on-navigation
999.0.0
npm
react-transition-group-legacy
100.0.0
npm
react-transition-group-legacy
99.9.9
npm
rules-deployer
0.0.0
npm
rules-playground
0.0.3
npm
shop-state
999.0.0
npm
shop-state
999.1.0
npm
shreddit.styles
0.0.1-security
npm
shreddit.styles
9.9.9
npm
spire.officejs-common
0.0.1-security
npm
spire.officejs-common
1.0.0
npm
spire.officejs-common
99.0.1
npm
spire.officejs-document
0.0.1-security
npm
spire.officejs-document
1.0.0
npm
spire.officejs-document
99.0.1
npm
spire.officejs-editors
0.0.1-security
npm
spire.officejs-editors
1.0.0
npm
spire.officejs-editors
99.0.1
npm
spire.officejs-externs
0.0.1-security
npm
spire.officejs-externs
99.0.1
1-50 of 55
sonatype-2026-000009 | Components Impacted | Sonatype Guide | Sonatype Guide