# sonatype-2026-001275

Malicious Packages - Wed Mar 18 2026 [Credential Info Stealer]

Published Mar 19, 2026

**CVSS Score**: High 7.1

## Security Details

### Components Impacted

### Sonatype Research

#### sonatype-2026-001275 Security Details

**CVE ID**: sonatype-2026-001275  
**CVE Description**: Malicious Packages - Wed Mar 18 2026 [Credential Info Stealer]
  
**Published**: Mar 19, 2026

**CVSS Score & Severity**: 7.1 High

**CVSS Vector**: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

**EPSS Score**: 0%

### Malware

malware

**KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

affected

**Source**: Sonatype

## References

- [Sonatype Help](https://help.sonatype.com/en/sonatype-malware-data.html)  
- [OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2026-2132.json)
