logo

IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations

ID: 51a43d16-9fef-5d5f-b70e-75f353a8f11b

STIX ID: report--51a43d16-9fef-5d5f-b70e-75f353a8f11b

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2023-10-31

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs analyzed an ongoing supply-chain malware campaign targeting the NuGet ecosystem since August 2023, in which attackers published hundreds of typosquatted packages that deliver Stage 2 payloads; recently they evolved from using install/init PowerShell scripts to abusing NuGet/MSBuild .targets inline tasks to achieve code execution, complicating detection and increasing risk to developers and CI builds. The report describes sample packages, the novel execution technique (rooted in the IAmRoot concept), campaign linking to prior Phylum findings, actor operational behavior (download count pumping, typosquatting), and includes collected IOCs and remediation context.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.