NuGet Packages Exploited to Target Developers with Malware
ID: 4b244cee-ac45-5f61-9e9a-d6622486166c
STIX ID: report--4b244cee-ac45-5f61-9e9a-d6622486166c
Feed Name: HackRead
Researchers observed a multi-wave campaign abusing NuGet package typosquatting and an MSBuild import loophole to execute malicious code during project builds: attackers placed obfuscated downloaders and scripts in package build/.targets files (and previously in tools PowerShell scripts), sometimes using IL weaving, to silently run payloads on developer machines; NuGet removed malicious packages quickly, but the technique demonstrates a persistent software-supply-chain risk that remains unresolved.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
