Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
sonatype-2026-000641
sonatype-2026-000641
Malicious Packages - Mon Mar 02 2026 [Lazarus] [Dropper]
Published Mar 2, 2026
https://help.sonatype.com/en/sonatype-malware-data.html
CVSS Score
High
8.7
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
npm
argon-node
3.5.7
npm
argon-web3-chain
2.4.5
npm
argonnode
2.4.5
npm
chai-as-chain
1.2.2
npm
chai-as-chain
1.2.3
npm
chai-as-chain
1.2.4
npm
chai-as-chains
1.2.4
npm
chai-chain-argon
3.5.7
npm
chai-chain-cognivault
2.3.5
npm
chai-chain-neurograde
2.3.5
npm
chai-chain-sinon
2.4.5
npm
chain-argon
2.4.5
npm
chain-cognivault
2.3.5
npm
chain-coremesh
2.3.5
npm
chain-multer
3.5.7
npm
chain-neurograde
2.4.7
npm
el-icon
1.1.9
npm
el-icon
1.2.1
npm
el-icon
1.2.2
npm
node-argon
2.4.5
npm
node-cognivault
2.3.5
npm
node-coremesh
2.3.5
npm
node-multer
3.5.7
npm
node-neurograde
2.4.7
npm
nodecognivault
2.3.5
npm
nodeneurograde
2.3.5
npm
shield-node
2.4.5
npm
sinon-node
2.4.5
npm
sinon-web3-chain
2.4.5
npm
web3-chain-sinon
3.5.7
1-30 of 30
sonatype-2026-000641 | Components Impacted | Sonatype Guide | Sonatype Guide