Typosquatting 2025 Incident #29

Maven Jackson typosquat

Estimated Financial Impact
First sophisticated Maven Central malware
Blast Radius
TLD prefix swap; encrypted C2

What Happened

A malicious package under org.fasterxml.jackson.core mimicked the legitimate com.fasterxml.jackson.core via a TLD prefix swap. It contained multi-staged payloads, encrypted C2, and platform-specific executables. First sophisticated malware detected on Maven Central.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCH

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← BoltDB Go typosquat @typescript_eslinter scope spoof →