VYPR

maven · Malicious package advisory

Malware

io.github.leetcrunch:scribejava-core

GHSA-9c6j-xrpw-g32x

Malicious code in io.github.leetcrunch:scribejava-core (Maven)

Details

**Severity:** Critical

**Affected versions:** `> 0`

---
_-= Per source details. Do not edit below this line.=-_

## Source: google-open-source-security (8dd884cda209e50c2bd5185172f3c25968cb972cbd19234779b43f4f855f2d26)
A malicious Maven Java package a typosquatting a legitimate OAuth Maven
package. The malicious package collects and exfils OAuth credentials on
the 15th day of each month.

**References:**
- https://github.com/ossf/malicious-packages/blob/59e9fd7d5ff138803baea71d5df869fe93d62782/osv/malicious/maven/io.github.leetcrunch:scribejava-core/MAL-2025-2552.json
- https://github.com/ossf/malicious-packages/blob/a38ecee305c88a229e05893a0413264b62143ce2/osv/malicious/maven/io.github.leetcrunch:scribejava-core/MAL-2025-2552.json
- https://socket.dev/blog/malicious-maven-package-exfiltrates-oauth-credentials
- https://github.com/ossf/malicious-packages/blob/752e8a991f186423e3415980200bebfec22d1070/osv/malicious/maven/io.github.leetcrunch:scribejava-core/MAL-2025-2552.json
- https://github.com/advisories/GHSA-9c6j-xrpw-g32x

Compromised versions (1)

  • > 0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.