⤷ Title: Socket Uncovers Malicious NuGet Typosquat “Netherеum.All” Exfiltrating Wallet Keys via Solana-Themed C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:35:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET #crypto wallet theft #Homoglyph #Nethereum #NuGet #Supply Chain #Typosquatting #XOR Obfuscation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Oct 2025 00:35:05 +0000
════════════════════════
⌗ Tags: #Malware #.NET #crypto wallet theft #Homoglyph #Nethereum #NuGet #Supply Chain #Typosquatting #XOR Obfuscation
Daily CyberSecurity
Socket Uncovers Malicious NuGet Typosquat “Netherеum.All” Exfiltrating Wallet Keys via Solana-Themed C2
A NuGet typosquat named Netherеum.All used a Cyrillic homoglyph to fool 11M+ downloads. The malicious package injected an XOR-decoded backdoor to steal crypto wallet and private key data.
⤷ Title: NuGet Sabotage: Time-Delayed Logic in 9 Packages Risks Total App Destruction on Hardcoded Dates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:35:37 +0000
════════════════════════
⌗ Tags: #Malware #Destructive Payload #NuGet #PLC #Ransomware_as_a_Service #Shanhai666 #Sharp7Extend #supply chain attack #Time_Delayed Logic
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 00:35:37 +0000
════════════════════════
⌗ Tags: #Malware #Destructive Payload #NuGet #PLC #Ransomware_as_a_Service #Shanhai666 #Sharp7Extend #supply chain attack #Time_Delayed Logic
Daily CyberSecurity
NuGet Sabotage: Time-Delayed Logic in 9 Packages Risks Total App Destruction on Hardcoded Dates
A NuGet supply chain attack injected time-delayed destructive logic into 9 packages. The malware triggers random crashes and silent data corruption on hardcoded future dates, targeting database/PLC applications.
⤷ Title: 2027 Time Bomb: Covert NuGet Packages Target SQL and PLCs with Scheduled Sabotage
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 02:53:09 +0000
════════════════════════
⌗ Tags: #Malware #.NET #cybersecurity #IndustrialControl #NuGet #PLC #PostgreSQL #sabotage #SQLServer #SupplyChainAttack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 10 Nov 2025 02:53:09 +0000
════════════════════════
⌗ Tags: #Malware #.NET #cybersecurity #IndustrialControl #NuGet #PLC #PostgreSQL #sabotage #SQLServer #SupplyChainAttack
Penetration Testing Tools
2027 Time Bomb: Covert NuGet Packages Target SQL and PLCs with Scheduled Sabotage
Nine NuGet packages were found with covert code scheduled to activate in 2027-2028, targeting SQL databases and Siemens PLCs with sudden process terminations.
⤷ Title: 5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 16 Dec 2025 01:45:36 +0000
════════════════════════
⌗ Tags: #Malware #.NET #Crypto Stealer #Fody #Homoglyph #NuGet #Stratis #supply chain attack #Tracer.Fody.NLog #Typosquatting
Daily CyberSecurity
5-Year Threat: Malicious NuGet Package Used Homoglyphs and Typosquatting to Steal Crypto Wallets
A malicious NuGet package (Tracer.Fody.NLog) stole crypto wallet data for 5 years using homoglyphs and typosquatting to evade detection. The .NET supply chain attack linked to a Russian C2 server.
⤷ Title: 14 Malicious NuGet Packages Found Stealing Crypto Wallets and Ad Data
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 18:13:14 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Malware #Scams and Fraud #Security #Crypto #Cyber Attack #Cybersecurity #Fraud #NuGet #ReversingLabs #Scam
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 18:13:14 +0000
════════════════════════
⌗ Tags: #Cyber Attacks #Malware #Scams and Fraud #Security #Crypto #Cyber Attack #Cybersecurity #Fraud #NuGet #ReversingLabs #Scam
Hackread
14 Malicious NuGet Packages Found Stealing Crypto Wallets and Ad Data
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: The Five-Year Sleeper: Malicious NuGet Package Poses as Tracer.Fody to Drain Crypto Wallets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:35:24 +0000
════════════════════════
⌗ Tags: #Malware #.NET #cybersecurity #Homoglyph Attack #Info_stealer #NuGet #Socket Threat Research #Stratis Wallet #supply chain attack #Tracer.Fody #Typosquatting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 18 Dec 2025 03:35:24 +0000
════════════════════════
⌗ Tags: #Malware #.NET #cybersecurity #Homoglyph Attack #Info_stealer #NuGet #Socket Threat Research #Stratis Wallet #supply chain attack #Tracer.Fody #Typosquatting
Penetration Testing Tools
The Five-Year Sleeper: Malicious NuGet Package Poses as Tracer.Fody to Drain Crypto Wallets
A covert threat has been uncovered within the .NET ecosystem, stemming from the substitution of a widely used
⤷ Title: Poisoned Dependencies: How Nethereum.All and 10M+ Fake Downloads Looted .NET Crypto Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET #Blockchain security #Cryptocurrency Theft #Malicious packages #Nethereum.All #NuGet #ReversingLabs #supply chain attack #Typosquatting #Wallet drainer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:26:49 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET #Blockchain security #Cryptocurrency Theft #Malicious packages #Nethereum.All #NuGet #ReversingLabs #supply chain attack #Typosquatting #Wallet drainer
Daily CyberSecurity
Poisoned Dependencies: How Nethereum.All and 10M+ Fake Downloads Looted .NET Crypto Developers
ReversingLabs uncovered Nethereum.All, a malicious NuGet package with 10M+ fake downloads designed to drain crypto wallets and steal API secrets.
⤷ Title: Malicious NuGet Packages Weaponize ASP.NET Identity for Production Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Security #C2 Server #Identity and Access Management #infosec #Malware Dropper #NCryptYo #NuGet Attack #Socket Threat Research #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 00:13:36 +0000
════════════════════════
⌗ Tags: #Malware #ASP.NET Security #C2 Server #Identity and Access Management #infosec #Malware Dropper #NCryptYo #NuGet Attack #Socket Threat Research #supply chain attack #Typosquatting
Daily CyberSecurity
Malicious NuGet Packages Weaponize ASP.NET Identity for Production Backdoors
Socket researchers uncover a NuGet supply chain attack using "NCryptYo" to hijack ASP.NET apps. Attackers inject backdoors into production authorization layers.
⤷ Title: Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:25:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET Security #Financial Cybercrime #infosec #malware #NuGet #Package Impersonation #ReversingLabs #Stripe.net #supply chain attack #Typosquatting
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 27 Feb 2026 04:25:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #.NET Security #Financial Cybercrime #infosec #malware #NuGet #Package Impersonation #ReversingLabs #Stripe.net #supply chain attack #Typosquatting
Daily CyberSecurity
Hackers Impersonate Stripe.net to Hijack the Global Payment Supply Chain
ReversingLabs uncovers a malicious NuGet package mimicking Stripe.net. Discover how attackers are targeting the financial sector via supply chain poisoning.
⤷ Title: Highly Evasive NuGet Supply Chain Attack Hijacks 65,000 .NET Build Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:04:59 +0000
════════════════════════
⌗ Tags: #Malware #.NET Security #AppBound Bypass #CI/CD security #cybersecurity #DevSecOps #infosec #IR.* Packages #malware #NuGet #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 09:04:59 +0000
════════════════════════
⌗ Tags: #Malware #.NET Security #AppBound Bypass #CI/CD security #cybersecurity #DevSecOps #infosec #IR.* Packages #malware #NuGet #supply chain attack
Daily CyberSecurity
Highly Evasive NuGet Supply Chain Attack Hijacks 65,000 .NET Build Servers
Critical alert: A stealth NuGet supply chain attack has hijacked 65,000 .NET workstations. Audit your CI/CD for malicious IR.* packages immediately.