Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Hackers Use NuGet Packages to Target .NET Developers
Hackers Use NuGet Packages to Target .NET Developers
Security

Hackers Use NuGet Packages to Target .NET Developers

October 5, 2023No Comments2 Mins Read

Threat actors have been observed using the open source package manager NuGet to craft malicious packages targeting .NET developers.

According to software package management company JFrog, the discovery would represent the first instance in the wild of packages with malicious code found in NuGet.

“For the first time, the NuGet repository – once thought to be untouched by malicious code – actually contains several harmful software packages designed to run automatically and often connected to further infected dependencies,” explained Shachar Menashe, senior director at JFrog Security Research. “This proves that no open source repository is safe from malicious actors.”

Read more on malware targeting open-source repositories here: Researchers Uncover 700+ Malicious Open Source Packages

According to an advisory written by JFrog security researchers Natan Nehorai and Brian Moussalli, the packages were downloaded 150,000 times over the past month.

“[They] contained a ‘download & execute’ type of payload […]. A PowerShell script that would execute upon installation and trigger a download of a ‘2nd stage’ payload, which could be remotely executed. The 2nd stage payload is a custom, more sophisticated executable,” wrote Nehorai and Moussalli.

The second-stage payload delivers several capabilities that include a crypto stealer, an Electron archive extractor (which also supports code execution) and an auto-updater.

In the advisory, the JFrog security experts said that upon contacting NuGet administrators, they were told the team were aware of the malicious package and had removed them.

Still, Menashe said that .NET developers are still at high risk from malicious code, considering that the observed NuGet packages still contain facilities to run code upon package installation.

See also  SlowMist Reports $174K AI Agent Exploit on Base Chain Highlights Trust Model Flaws

“Even though the culpable malicious packages have […] been removed, .NET developers using NuGet are still at high risk of malicious code infecting their environments,” the executive added. “[They] should take caution when curating open-source components for use in their builds – and at every step of the software development lifecycle – to ensure the software supply chain remains secure.”

For additional information about securing open source software, head over to this analysis by OpenUK CEO, Amanda Brock.

Source link

Developers hackers net NuGet Packages Target

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

LayerZero says it ‘made a mistake’ in $292 Million Kelp exploit

May 11, 2026

AAVE Price Prediction: $105 Target Faces $80 Support Test – Critical 30-Day Crossroads

April 25, 2026

VanEck to Donate ETF 10% Profit to Ethereum Protocol Guild

September 30, 2023

Type above and press Enter to search. Press Esc to cancel.