Threat Management, Threat Intelligence

Maven Central subjected to typosquatted Jackson JSON library

A person's hand holds a magnifying glass over an alert symbol on a cybersecurity interface. The image suggests security issues and vigilance.

Maven Central, the leading Java dependency repository, has been targeted by the malicious "org.fasterxml.jackson.core" package that masquerades as the legitimate Jackson JSON library, which has been taken down within an hour and a half of its disclosure, GBHackers News reports.

Integrated into the typosquatted package was a trojan downloader enabling multi-stage malware compromise, with @Configuration annotations used by the malware to enable automated execution, according to an analysis from Aikido researchers.

After checking for a persistence marker file, the malware proceeds to fingerprint the targeted system before forming command-and-control server communications. AES-encrypted configuration strings with platform-specific payload URLs are then decrypted by the malware through a hardcoded 16-character key, with operating system-specific binaries injected for Windows systems, while macOS and Linux systems are given unsigned executables, which were noted to be Cobalt Strike beacons.

Such findings should prompt the adoption of prefix-similarity namespace detection in Maven Central.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds