# sonatype-2022-1754

## vapi-client-bindings at 26 March 2022 - Malicious Package

Published Mar 28, 2022

**CVSS Score:** Critical 10.0

### Security Details

**CVE ID:** sonatype-2022-1754  
**CVE Description:** vapi-client-bindings at 26 March 2022 - Malicious Package  
**Published:** Mar 29, 2022  
**CVSS Score & Severity:** 10.0 Critical  
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H  
**EPSS Score:** 0%

### Malware

**KEV Status:** Not in KEV Catalog: No known exploits

### Affected Ecosystems

**Source:** Sonatype

### References

- [Sonatype Malware Data](https://help.sonatype.com/en/sonatype-malware-data.html)  
- [Sonatype Blog](/content/blog/vmware-vsphere-dependency-confusion-attempt-caught-by-sonatype/index.html)
