
NuGet malware targets Nethereum tools
Highlighting an alarming trend, RL has discovered malicious packages targeting crypto wallets and OAuth tokens to steal funds.

Threat Researcher, ReversingLabs.
find Petar Kirhmajer on:

Highlighting an alarming trend, RL has discovered malicious packages targeting crypto wallets and OAuth tokens to steal funds.

RL researchers have identified 19 malicious extensions on the VS Code Marketplace — the majority containing a malicious file posing as a PNG.

ETHcode, a VS Code extension for Ethereum smart contract development, was compromised following a GitHub pull request.

Here's what the RL research team knows about the suspicious SqzrFramework480 campaign, which is still available on the NuGet repository.

RL discovered two malicious packages and a subsequent larger campaign, showing that the approach is an emerging software supply chain attack method.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial