logo

Inside the NuGet hackers' toolset

ID: 91125374-e7c8-5eca-8951-15a819c045ab

STIX ID: report--91125374-e7c8-5eca-8951-15a819c045ab

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2026-02-26

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs researchers discovered two NuGet packages that accidentally contained a complete three-part attacker toolchain for large-scale NuGet typosquatting: a scrapper that clones package metadata, a publisher that creates and uploads semi-empty impersonating packages (including future inflated versions), and a multi-threaded PowerShell 'botter' that fakes downloads via rotated user-agents and proxies to artificially boost perceived trust; the exposure confirms how threat actors operationalize metadata cloning and reputation manipulation in supply-chain campaigns and provides behavioral indicators for defenders to detect and block similar abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.