Domain Acquisition 2024 Incident #53

MavenGate

Estimated Financial Impact
$10-100M+ potential
Blast Radius
18% of Maven dependencies hijackable

What Happened

Researchers at Oversecured discovered that 18%+ of Maven Central dependencies had associated domains that had expired or were purchasable. An attacker purchasing such a domain could publish malicious versions of abandoned but widely-used Java/Android libraries. Reports were sent to 200+ affected companies including Google, Facebook, and Amazon.

○

Risk Guard: Partial

PACKAGE_REGISTRY_MISMATCH + PACKAGE_UNSAFE_SOURCE_URL flag expired domain resolution

Risk Guard Check Codes That Flag This Incident

PACKAGE_REGISTRY_MISMATCHPACKAGE_UNSAFE_SOURCE_URL

How Every Tool Performed

0 Caught 2 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Partial PACKAGE_REGISTRY_MISMATCH + PACKAGE_UNSAFE_SOURCE_URL flag expired domain resolution
Sonatype (Nexus) Partial Repository management could theoretically flag; not documented capability
Socket Missed Maven resolution layer outside package analysis scope
Snyk Missed No Maven domain expiry monitoring
Black Duck Missed No domain expiry monitoring
Endor Labs Missed No domain expiry monitoring
← Polyfill.io domain takeover Log4Shell (CVE-2021-44228) →