logo

Dubious NuGet Package May Portend Chinese Industrial Espionage

ID: 2046da4d-600b-5445-8526-5be533189e68

STIX ID: report--2046da4d-600b-5445-8526-5be533189e68

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-03-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers flagged a NuGet package named SqzrFramework480 that contains an Init method which decodes a concealed IP address, pings it, opens a socket, captures screenshots, and sends the data—behaviors consistent with potential industrial-espionage malware; the package is live on NuGet with ~3,000 downloads and exhibits obfuscation and suspicious account history, though active exploitation has not been confirmed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.