Nine malicious NuGet packages have been found to be able to disrupt industrial control systems and interfere with database operations by dropping time-delayed payloads.
The packages were released in 2023 and 2024 by a user known as “shanhai666” and are intended to execute malicious code following particular trigger dates in August 2027 and November 2028, according to software supply chain security firm Socket. Together, 9,488 downloads of the packages were made.
According to security researcher Kush Pandya, the most dangerous package, Sharp7Extend, targets industrial PLCs with dual sabotage mechanisms: immediate random process termination and silent write failures that start 30 to 90 minutes after installation, impacting safety-critical systems in manufacturing environments.
Below is a list of harmful packages read more about Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
