Maven Central, the leading Java dependency repository, has been targeted by the malicious "org.fasterxml.jackson.core" package that masquerades as the legitimate Jackson JSON library, which has been taken down within an hour and a half of its disclosure, GBHackers News reports.
Integrated into the typosquatted package was a trojan downloader enabling multi-stage malware compromise, with @Configuration annotations used by the malware to enable automated execution, according to an analysis from Aikido researchers.
After checking for a persistence marker file, the malware proceeds to fingerprint the targeted system before forming command-and-control server communications. AES-encrypted configuration strings with platform-specific payload URLs are then decrypted by the malware through a hardcoded 16-character key, with operating system-specific binaries injected for Windows systems, while macOS and Linux systems are given unsigned executables, which were noted to be Cobalt Strike beacons.
Such findings should prompt the adoption of prefix-similarity namespace detection in Maven Central.
Integrated into the typosquatted package was a trojan downloader enabling multi-stage malware compromise, with @Configuration annotations used by the malware to enable automated execution, according to an analysis from Aikido researchers.
After checking for a persistence marker file, the malware proceeds to fingerprint the targeted system before forming command-and-control server communications. AES-encrypted configuration strings with platform-specific payload URLs are then decrypted by the malware through a hardcoded 16-character key, with operating system-specific binaries injected for Windows systems, while macOS and Linux systems are given unsigned executables, which were noted to be Cobalt Strike beacons.
Such findings should prompt the adoption of prefix-similarity namespace detection in Maven Central.




