logo

Suspicious NuGet package grabs data from industrial systems

ID: 6b9ce4a2-33af-505a-9788-990d362c628b

STIX ID: report--6b9ce4a2-33af-505a-9788-990d362c628b

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2024-03-26

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs discovered a suspicious NuGet package, SqzrFramework480, containing a .NET library (SqzrFramework480.dll) that continuously takes screenshots and sends them via sockets to a remote IP; the package appears tailored to BOZHON industrial/vision tooling and may be a supply-chain espionage attempt, though researchers could not definitively attribute or confirm active exploitation and the package remains available with thousands of downloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.