9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
socket.dev·5h
Flag this post

Socket’s Threat Research Team discovered nine malicious NuGet packages that inject time-delayed destructive payloads into database operations and target industrial control systems. Published under the NuGet alias shanhai666 between 2023 and 2024, these packages terminate the host application process with 20% probability on each database query after specific trigger dates in 2027 and 2028.

The most dangerous package, Sharp7Extend, targets industrial PLCs with dual sabotage mechanisms: immediate random process termination and silent write failures that begin 30-90 minutes after installation, affecting safety-critical systems in manufacturing environments.

The nine malicious packages published by the threat actor accumulated 9,488 downloads. We’ve reported these packages to NuGet on…

Similar Posts

Loading similar posts...