IAmReboot: Malicious NuGet packages exploit loophole in MSBuild integrations
ID: 51a43d16-9fef-5d5f-b70e-75f353a8f11b
STIX ID: report--51a43d16-9fef-5d5f-b70e-75f353a8f11b
Feed Name: ReversingLabs Blog
ReversingLabs analyzed an ongoing supply-chain malware campaign targeting the NuGet ecosystem since August 2023, in which attackers published hundreds of typosquatted packages that deliver Stage 2 payloads; recently they evolved from using install/init PowerShell scripts to abusing NuGet/MSBuild .targets inline tasks to achieve code execution, complicating detection and increasing risk to developers and CI builds. The report describes sample packages, the novel execution technique (rooted in the IAmRoot concept), campaign linking to prior Phylum findings, actor operational behavior (download count pumping, typosquatting), and includes collected IOCs and remediation context.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
