logo

Malicious NuGet packages drop disruptive 'time bombs'

ID: 0aef29f3-99cc-5e3d-9111-3c08c574131d

STIX ID: report--0aef29f3-99cc-5e3d-9111-3c08c574131d

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-07

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Malicious NuGet packages with delayed sabotage payloads:** Nine NuGet packages published under the 'shanhai666' account bundled mostly legitimate .NET libraries with a small malicious payload that uses C# extension methods and probabilistic triggers to randomly terminate database/PLC processes or corrupt Siemens S7 PLC writes between 2027–2028 (notably Sharp7Extend), posing a supply‑chain risk to applications and industrial environments; organizations should audit for the listed packages and verify PLC/write integrity and safety logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.