NuGet is a technology platform tracked across 16 threat clusters and 26 intelligence report mentions on ThreatCluster. First observed November 7, 2025; most recent activity July 22, 2026.
Five malicious NuGet packages were discovered targeting developers in the Chinese .NET ecosystem. The packages, published under the account bmrxntfj, impersonate legitimate libraries and have accumulated around 65,000…
On April 21, 2026, Microsoft released an emergency out-of-band update, .NET 10.0.7, to address a critical privilege escalation vulnerability tracked as CVE-2026-40372. This flaw, found in the ASP.NET Core Data…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A malicious NuGet package named 'Newtonsoftt.Json.Net' was discovered, targeting the Digitain betting platform by rigging game results. The package, which mimicked the legitimate Newtonsoft.Json library, was downloaded…
A malicious NuGet package named 'Sicoob.Sdk' has been identified, which impersonates an official software development kit for Sicoob, a major Brazilian cooperative financial system. This package, affecting versions…
Eleven malicious NuGet packages disguised as game cheats and automation tools have been identified, deploying a Windows payload known as pepesoft.exe. These packages target gaming communities, particularly for titles…
On June 11, 2026, RapidFort announced the launch of RapidFort Curated Libraries, a catalog of malware-scanned open-source libraries aimed at preventing supply chain malware from infiltrating development pipelines. The…
Chainguard and Cursor have partnered to improve security in agentic software development by providing secure-by-default open source artifacts. This collaboration aims to close the software supply chain trust gap, as 84%…
Malicious NuGet packages have been identified that mimic the Nethereum library, targeting crypto wallets and OAuth tokens. Users of .NET applications integrating these libraries are at risk of having their credentials…
Researchers identified nine malicious NuGet packages containing time-delayed sabotage routines targeting .NET applications and industrial control systems. The packages, downloaded nearly 9,500 times, include…