logo

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

ID: 4cb06255-a626-520d-8947-34f1c901424b

STIX ID: report--4cb06255-a626-520d-8947-34f1c901424b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: [email protected] (The Hacker News)

...
...

Security researchers discovered a malicious NuGet package named "Sicoob.Sdk" that was distributed on NuGet and secretly exfiltrated PFX certificates, PFX passwords, and client IDs to a hardcoded third-party Sentry endpoint—allowing attackers to impersonate Sicoob API integrations and access downstream financial data; the package has been removed from NuGet. The report places this incident among a wave of active supply-chain campaigns across npm and other registries (typosquatting, postinstall credential harvesters, dependency confusion) and highlights links to known threat actors like TeamPCP/Replicating Marauder.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.