logo

NuGet malware targets Nethereum tools

ID: 6ff55be7-e1ad-5f6f-9fcc-fb0640078403

STIX ID: report--6ff55be7-e1ad-5f6f-9fcc-fb0640078403

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2025-12-17

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs discovered a NuGet supply‑chain campaign comprising 14 malicious packages that impersonated legitimate .NET crypto libraries and quietly embedded malicious functions to exfiltrate private keys/seed phrases, overwrite transaction destinations to attacker wallets, and steal Google Ads OAuth credentials; techniques used included homoglyphs, version bumping, and inflated download counts to appear legitimate. The report categorizes the packages into three groups (wallet stealer, crypto-funds stealer, Google Ads OAuth stealer), provides examples of malicious functions and IOCs, and recommends developer vetting, package inspection, and defensive tools to mitigate downstream compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.