# sonatype-2025-000924

Malicious Packages - Wed Mar 26 2025 \[Credential Info Stealer\]

Published Mar 26, 2025

CVSS Score High

7.1

## Security Details

### Components Impacted

### sonatype-2025-000924 Security Details

**CVE ID**  sonatype-2025-000924  
**CWE** N/A  
**CVE Description** Malicious Packages - Wed Mar 26 2025 \[Credential Info Stealer\]  
**Published** Mar 26, 2025

### CVSS Score & Severity

7.1 High

### CVSS Vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

### EPSS Score

0%

### Malware

malware

### KEV Status

Not in KEV Catalog: No known exploits

### Affected Ecosystems

affected

**Source**  Sonatype

### References

[help.sonatype.com](https://help.sonatype.com/en/sonatype-malware-data.html) THIRD_PARTY  
[sonatype.com](/content/blog/multiple-crypto-packages-hijacked-turned-into-info-stealers/index.html) THIRD_PARTY
