logo

11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

ID: 17ba946b-73c7-55d2-961a-6e8bdcae7ce7

STIX ID: report--17ba946b-73c7-55d2-961a-6e8bdcae7ce7

Feed Name: Socket Blog

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: Kush Pandya

...
...

**Executive summary:** Socket’s Threat Research Team analyzed 11 malicious NuGet DotnetTool packages that masquerade as game utilities and download a staged PyInstaller Windows payload (pepesoft.exe) from GitHub/Hugging Face under the operator "pepegit666"; the multi-stage toolset uses DNS-over-HTTPS resolution, elevation for clock resync, embedded AWS-style credentials to retrieve remote configuration, Google Sheets-backed telemetry/licensing (including a remote ban-list and hardware binding), and in some builds Telegram-based screenshot/remote-control features — the report includes behavioral analysis, recovered payloads, IOCs (hashes, URLs, keys, mutex), and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.