logo

Malicious NuGet Package Linked to Industrial Espionage Targets Developers

ID: 75bff325-98d9-5b06-a949-455c521c20b9

STIX ID: report--75bff325-98d9-5b06-a949-455c521c20b9

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-03-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Threat researchers identified a malicious NuGet package, SqzrFramework480, which contained a DLL that continuously captured screenshots, performed heartbeat pings to a remote IP, and transmitted images over a socket; analysts believe it may be aimed at industrial systems (cameras, machine vision, robotic arms) for espionage purposes. The package was downloaded ~2,999 times before being removed from NuGet, and while researchers note plausible benign explanations, the combination of behaviors is considered suspicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.