-= Per source details. Do not edit below this line.=-
A malicious Maven Java package a typosquatting a legitimate OAuth Maven package. The malicious package collects and exfils OAuth credentials on the 15th day of each month.
{
"malicious-packages-origins": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"modified_time": "2025-03-19T23:55:30Z",
"sha256": "8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26",
"import_time": "2025-03-20T00:02:04.794639Z",
"source": "google-open-source-security"
}
]
}