logo

11 Malicious NuGet Packages Pose as Game Cheats to Deploy Windows Surveillance Malware

ID: a194bfd5-7dc6-5400-b250-a59c7482a4bb

STIX ID: report--a194bfd5-7dc6-5400-b250-a59c7482a4bb

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Varshini

...
...

Socket’s Threat Research Team identified 11 malicious NuGet DotnetTool packages masquerading as game cheats and panels that install a two-stage Windows surveillance payload (pepesoft.exe). The downloader (bundled as a .NET tool) retrieves a PyInstaller-packed second stage that fingerprints devices, enforces remote HWID bans, reports status and licensing to operator-controlled Google Sheets, and in some builds captures and exfiltrates screenshots via a Telegram bot; packages targeted multiple online game communities and were reported to NuGet for removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.