Thehackernews
Malicious NuGet Package Targets Sicoob SDK, Exfiltrates Banking Credentials
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A malicious NuGet package named 'Sicoob.Sdk' has been identified, which impersonates an official software development kit for Sicoob, a major Brazilian cooperative financial system. This package, affecting versions 2.0.0 to 2.0.4, is designed to exfiltrate sensitive banking credentials, including client IDs and PFX certificates. The attack specifically targets developers integrating with Sicoob's banking APIs, raising significant concerns about software supply chain security in the financial sector. Cybersecurity researchers from Socket confirmed the malicious functionality of the package, which has the potential to compromise numerous banking accounts. The discovery was made public on May 29, 2026, prompting immediate warnings for developers to avoid using the compromised package. The full scope of the impact remains unclear, but the incident highlights vulnerabilities in software supply chains.
Key Points: • A malicious NuGet package masquerading as Sicoob SDK has been discovered. • The package exfiltrates sensitive banking credentials, including client IDs and PFX certificates. • Versions 2.0.0 to 2.0.4 of 'Sicoob.Sdk' are confirmed to be compromised.