Suspicious NuGet package grabs data from industrial systems
ID: 6b9ce4a2-33af-505a-9788-990d362c628b
STIX ID: report--6b9ce4a2-33af-505a-9788-990d362c628b
Feed Name: ReversingLabs Blog
Threat Score
ReversingLabs discovered a suspicious NuGet package, SqzrFramework480, containing a .NET library (SqzrFramework480.dll) that continuously takes screenshots and sends them via sockets to a remote IP; the package appears tailored to BOZHON industrial/vision tooling and may be a supply-chain espionage attempt, though researchers could not definitively attribute or confirm active exploitation and the package remains available with thousands of downloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
