logo

14 Malicious NuGet Packages Found Stealing Crypto Wallets and Ad Data

ID: 0b7517b6-e986-52d0-80d9-2ded562479e4

STIX ID: report--0b7517b6-e986-52d0-80d9-2ded562479e4

Feed Name: HackRead

Threat Score
78/100

Date Published: 2025-12-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

ReversingLabs uncovered a supply-chain campaign on NuGet involving 14 malicious packages that impersonated popular libraries (e.g., "Netherеum.All") to steal crypto seed phrases and private keys, swap cryptocurrency transaction destinations for amounts over $100, and steal OAuth tokens (e.g., affecting Google Ads). The operators used homoglyphs, rapid version bumps, and artificially inflated download counts to appear legitimate; one author linked to prior theft-related packages (DamienMcdougal). Because these packages can be included in downstream projects, the campaign poses a significant risk to developers and end users, enabling broad financial theft and credential misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.