Skip to content
ThreatCluster

Malware Campaign Targets Maven Central via Jackson JSON Library Impersonation

First seen 30 Dec 2025, 19:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A malware campaign has infiltrated Maven Central by impersonating a legitimate Jackson JSON library extension. The malicious package was published under the org.fasterxml.jackson.core/jackson-databind namespace, marking a significant instance of a typosquatting attack on this trusted repository for Java developers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)