Bleepingcomputer
Malicious NuGet Packages Set to Activate Time Bombs in 2027 and 2028
First seen 2 Dec 2025, 18:33 UTC
•



•8.3
Export
Article Content
Browse articles
Nine malicious NuGet packages, published by the user 'shanhai666', were identified to contain time-delayed sabotage payloads targeting industrial control systems and applications. These packages, which have been downloaded 9,488 times, are designed to activate between 2027 and 2028, using probabilistic triggers to execute their malicious routines. An investigation and removal efforts have been initiated by NuGet following their discovery.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
Rapid7 Reports Surge in Vulnerability Exploitation Outpacing Patching Efforts
ACSC Issues Critical Alert on Exploited CMS Vulnerabilities
Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs