Malicious NuGet packages drop disruptive 'time bombs'
ID: 0aef29f3-99cc-5e3d-9111-3c08c574131d
STIX ID: report--0aef29f3-99cc-5e3d-9111-3c08c574131d
Feed Name: Bleeping Computer
**Malicious NuGet packages with delayed sabotage payloads:** Nine NuGet packages published under the 'shanhai666' account bundled mostly legitimate .NET libraries with a small malicious payload that uses C# extension methods and probabilistic triggers to randomly terminate database/PLC processes or corrupt Siemens S7 PLC writes between 2027–2028 (notably Sharp7Extend), posing a supply‑chain risk to applications and industrial environments; organizations should audit for the listed packages and verify PLC/write integrity and safety logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
