Malicious NuGet Package Targets Sicoob SDK, Exfiltrates Banking Credentials

Malicious NuGet Package Targets Sicoob SDK, Exfiltrates Banking Credentials

First seen 29 May 2026, 15:45 UTC ThehackernewsGbhackersCybersecuritynews 89% similarity 69.0

Article Content

Browse articles
ThreatCluster

A malicious NuGet package named 'Sicoob.Sdk' has been identified, which impersonates an official software development kit for Sicoob, a major Brazilian cooperative financial system. This package, affecting versions 2.0.0 to 2.0.4, is designed to exfiltrate sensitive banking credentials, including client IDs and PFX certificates. The attack specifically targets developers integrating with Sicoob's banking APIs, raising significant concerns about software supply chain security in the financial sector. Cybersecurity researchers from Socket confirmed the malicious functionality of the package, which has the potential to compromise numerous banking accounts. The discovery was made public on May 29, 2026, prompting immediate warnings for developers to avoid using the compromised package. The full scope of the impact remains unclear, but the incident highlights vulnerabilities in software supply chains.

Key Points: • A malicious NuGet package masquerading as Sicoob SDK has been discovered. • The package exfiltrates sensitive banking credentials, including client IDs and PFX certificates. • Versions 2.0.0 to 2.0.4 of 'Sicoob.Sdk' are confirmed to be compromised.

ThreatCluster AI

Timeline

2026-05-29
Malicious NuGet package identified
Cybersecurity researchers found a NuGet package impersonating Sicoob SDK that exfiltrates banking credentials.
The Hacker News
2026-05-29
Warnings issued to developers
Developers were advised to avoid using the compromised 'Sicoob.Sdk' package to protect sensitive information.
Cybersecuritynews

Community

Browse all →