logo

Sicoob SDK Banking Malware Exploits NuGet Developer Channels

ID: 0534bac5-7358-57f9-add9-50469f237b38

STIX ID: report--0534bac5-7358-57f9-add9-50469f237b38

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Ddos

...
...

**Executive summary:** A malicious NuGet package named Sicoob.Sdk was uploaded to the NuGet repository impersonating an official C# SDK for a major Brazilian financial cooperative; versions 2.0.0–2.0.4 exfiltrated PFX files, passwords, client IDs and transaction data to a hardcoded third-party endpoint during constructor-time execution, enabling credential theft and potential downstream access to financial APIs and CI/CD pipelines — NuGet has blocked the account, and organizations must remove the package, revoke and rotate exposed certificates/passwords, and audit for suspicious access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.