Skip to content

Hackers Infiltrated Maven Central Masquerading as a Legitimate Jackson JSON Library

Cybersecuritynews •Tushar Subhra Dutta • December 30, 2025

A new malware campaign has successfully infiltrated Maven Central, one of the most trusted repositories for Java developers, by masquerading as a legitimate Jackson JSON library extension. The malicious package, published under the org.fasterxml.jackson.core/jackson-databind namespace, represents one of the first instances of sophisticated malware discovered on Maven Central through a typosquatting attack. This attack takes […]

Extracted Entities

Platforms (1)