Dubious NuGet Package May Portend Chinese Industrial Espionage
ID: 2046da4d-600b-5445-8526-5be533189e68
STIX ID: report--2046da4d-600b-5445-8526-5be533189e68
Feed Name: Dark Reading
Threat Score
Researchers flagged a NuGet package named SqzrFramework480 that contains an Init method which decodes a concealed IP address, pings it, opens a socket, captures screenshots, and sends the data—behaviors consistent with potential industrial-espionage malware; the package is live on NuGet with ~3,000 downloads and exhibits obfuscation and suspicious account history, though active exploitation has not been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
