While version 0.0.4 is an older release, it is still sought after for specific legacy testing scenarios. Official Source
The security landscape is littered with "poisoned" binaries. Attackers often upload malicious JAR files to mirror sites, hoping to compromise pentesters. ysoserial-0.0.4-all.jar download
(Ubuntu example):
(Note: Hashes change per build; you should compile from source and compare against your own known-good version. A placeholder is shown below – replace with actual hash if known.) While version 0