logo

NuGet Packages Exploited to Target Developers with Malware

ID: 4b244cee-ac45-5f61-9e9a-d6622486166c

STIX ID: report--4b244cee-ac45-5f61-9e9a-d6622486166c

Feed Name: HackRead

Threat Score
72/100

Date Published: 2024-07-15

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Researchers observed a multi-wave campaign abusing NuGet package typosquatting and an MSBuild import loophole to execute malicious code during project builds: attackers placed obfuscated downloaders and scripts in package build/.targets files (and previously in tools PowerShell scripts), sometimes using IL weaving, to silently run payloads on developer machines; NuGet removed malicious packages quickly, but the technique demonstrates a persistent software-supply-chain risk that remains unresolved.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.