Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

HBAR Price Prediction: Consolidation at $0.09 Sets Stage for $0.13 Breakout

May 2, 2026

PROACTIS SA – Press Release (nomination R Archer and P Dennant)

May 2, 2026

USSS Chief Says Hilton Site Was ‘Set Up Perfectly,’ Critics Disagree

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Hackers Use NuGet Packages to Target .NET Developers
Hackers Use NuGet Packages to Target .NET Developers
Security

Hackers Use NuGet Packages to Target .NET Developers

October 5, 2023No Comments2 Mins Read

Threat actors have been observed using the open source package manager NuGet to craft malicious packages targeting .NET developers.

According to software package management company JFrog, the discovery would represent the first instance in the wild of packages with malicious code found in NuGet.

“For the first time, the NuGet repository – once thought to be untouched by malicious code – actually contains several harmful software packages designed to run automatically and often connected to further infected dependencies,” explained Shachar Menashe, senior director at JFrog Security Research. “This proves that no open source repository is safe from malicious actors.”

Read more on malware targeting open-source repositories here: Researchers Uncover 700+ Malicious Open Source Packages

According to an advisory written by JFrog security researchers Natan Nehorai and Brian Moussalli, the packages were downloaded 150,000 times over the past month.

“[They] contained a ‘download & execute’ type of payload […]. A PowerShell script that would execute upon installation and trigger a download of a ‘2nd stage’ payload, which could be remotely executed. The 2nd stage payload is a custom, more sophisticated executable,” wrote Nehorai and Moussalli.

The second-stage payload delivers several capabilities that include a crypto stealer, an Electron archive extractor (which also supports code execution) and an auto-updater.

In the advisory, the JFrog security experts said that upon contacting NuGet administrators, they were told the team were aware of the malicious package and had removed them.

Still, Menashe said that .NET developers are still at high risk from malicious code, considering that the observed NuGet packages still contain facilities to run code upon package installation.

See also  Rug Pull Schemes: Crypto Investor Losses Near $1M

“Even though the culpable malicious packages have […] been removed, .NET developers using NuGet are still at high risk of malicious code infecting their environments,” the executive added. “[They] should take caution when curating open-source components for use in their builds – and at every step of the software development lifecycle – to ensure the software supply chain remains secure.”

For additional information about securing open source software, head over to this analysis by OpenUK CEO, Amanda Brock.

Source link

Developers hackers net NuGet Packages Target

Related Posts

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026

Tax season fuels rise in crypto wallet scams, Kaspersky reports

May 2, 2026

Zondacrypto client data end up for sale on the darknet

May 2, 2026
Top Posts

Ultralife: Stock To Outperform With Growth From Multiple Industries

October 18, 2023

OpenClaw Creator Bans Bitcoin, Crypto Chatter After Joining OpenAI

February 24, 2026

Curve Price Spikes As Whales Suddenly Accumulate CRV: On-Chain Data

September 26, 2023

Type above and press Enter to search. Press Esc to cancel.