Researchers at Oversecured discovered that 18%+ of Maven Central dependencies had associated domains that had expired or were purchasable. An attacker purchasing such a domain could publish malicious versions of abandoned but widely-used Java/Android libraries. Reports were sent to 200+ affected companies including Google, Facebook, and Amazon.
PACKAGE_REGISTRY_MISMATCH + PACKAGE_UNSAFE_SOURCE_URL flag expired domain resolution
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Partial | PACKAGE_REGISTRY_MISMATCH + PACKAGE_UNSAFE_SOURCE_URL flag expired domain resolution |
| Sonatype (Nexus) | Partial | Repository management could theoretically flag; not documented capability |
| Socket | Missed | Maven resolution layer outside package analysis scope |
| Snyk | Missed | No Maven domain expiry monitoring |
| Black Duck | Missed | No domain expiry monitoring |
| Endor Labs | Missed | No domain expiry monitoring |