Tick Tock, Your Credentials Are Gone: The Maven Package With...
Blog post from Socket
A malicious Maven package masquerading as the popular scribejava-core OAuth library has been discovered, using typosquatting techniques to deceive Java developers and exfiltrate OAuth credentials on the 15th of each month. This package, uncovered by Socket's threat research team, employs obfuscated code and time-based triggers to evade detection, posing significant risks to developers who inadvertently integrate it into their projects. The attackers have created six dependent packages to enhance the perceived legitimacy of the malicious artifact, which shares a groupId (`io.github.leetcrunch`) similar to the real namespace (`com.github.scribejava`). This strategic timing and obfuscation complicate attribution and provide ongoing access to potentially updated credentials, highlighting the importance of vigilance in software supply chains. Security measures such as proactive scanning, artifact verification, and secret rotation are recommended to mitigate potential damage, alongside tools like the Socket GitHub app and CLI that detect anomalies in dependencies and downloads.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.