60 New Malicious Packages Uncovered in NuGet Supply Chain Attack
As part of a campaign that started in August 2023, threat actors have been seen implementing a new layer of stealth to avoid detection and distributing a fresh wave of malicious packages to the NuGet package management.
Software supply chain security company ReversingLabs stated that the new packages, which total roughly 60 and span 290 versions, show a more sophisticated methodology than the earlier batch that surfaced in October 2023.
Security researcher Karlo Zanki stated that the attackers changed their approach from utilizing NuGet's MSBuild integrations to one that employs straightforward, obfuscated downloaders that are inserted into authentic PE binary files using Intermediary Language (IL) Weaving, a.NET programming technique for altering an application's code after compila...

