Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2026-000640
sonatype-2026-000640
Malicious Packages - Mon Mar 02 2026 [Lazarus] [Dropper]
Published Mar 2, 2026
https://help.sonatype.com/en/sonatype-malware-data.html
https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-1298.json
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
fastjsonlog
1.1.12
npm
json-specparse
7.4.11
npm
json-spectaculation
3.10.14
npm
jsonify-core
0.0.1-security
npm
jsonify-core
4.1.12
npm
nodex-db
8.4.13
npm
nodex-db
8.5.10
npm
nodex-db
8.5.11
npm
safe-json-parsex
1.0.1
1-9 of 9
sonatype-2026-000640 | Components Impacted | Sonatype Guide | Sonatype Guide