logo

Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library

ID: 680aff36-fbfc-5a5a-a1c8-1569bdbdb8b9

STIX ID: report--680aff36-fbfc-5a5a-a1c8-1569bdbdb8b9

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A typosquatting supply-chain malware campaign uploaded a malicious jackson-databind package to Maven Central (org.fasterxml.jackson.core), leveraging namespace and domain confusion (fasterxml.org) to trick developers. The package auto-executes in Spring Boot apps, performs environment fingerprinting, retrieves AES-encrypted configuration from a hardcoded C2 (m.fasterxml.org:51211), downloads platform-specific payloads (including Cobalt Strike beacons), and uses persistence and evasion techniques; it was removed from Maven Central ~1.5 hours after discovery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.