
Inside the NuGet hackers' toolset
RL discovered two packages containing scripts that complete a typosquatting toolchain. Here's how it worked.

Threat Researcher, ReversingLabs.
find Petar Kirhmajer on:

RL discovered two packages containing scripts that complete a typosquatting toolchain. Here's how it worked.

Threat actors targeted developers with a bogus package — a shift away from the recent crypto development hack focus.

Highlighting an alarming trend, RL has discovered malicious packages targeting crypto wallets and OAuth tokens to steal funds.

RL researchers have identified 19 malicious extensions on the VS Code Marketplace — the majority containing a malicious file posing as a PNG.

ETHcode, a VS Code extension for Ethereum smart contract development, was compromised following a GitHub pull request.

Here's what the RL research team knows about the suspicious SqzrFramework480 campaign, which is still available on the NuGet repository.

RL discovered two malicious packages and a subsequent larger campaign, showing that the approach is an emerging software supply chain attack method.
Get your 14-day free trial of Spectra Assure
Get Free TrialMore about Spectra Assure Free Trial