RL Blog

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top
The inaugural Gartner® Magic Quadrant™ for Software Supply Chain Security is outGET THE REPORT
Skip to main content
Contact UsSupportBlogCommunity
reversinglabs
ReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseVerify AI Supply ChainIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
Events
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Products & TechnologyDecember 3, 2024

.Net Devs Can Now Vet NuGet Packages with the Spectra Assure Community

The RL community's search interface allows software development teams to quickly assess risk before choosing or updating open source NuGet packages.

Jasmine Noel, Senior Product Marketing Manager at ReversingLabs.Jasmine Noel
FacebookFacebookXX / TwitterLinkedIn
LinkedIn
blueskyBluesky
Email Us

Main Story

IntroSpectra Assure Community Adds Support for NuGet RepositoryValidate Safety of Open Source Updates

Curating open source code or compiled DLLs from the NuGet public package repository is a common practice for .NET developers. It is fairly easy to search for appropriate packages, and eliminates time spent reinventing wheels, axles, headlights, seat-belts, etc.. In a 2023 survey, 80% of respondents increased the use of open source in their organizations over the last year.

This ease and productivity boost of NuGet and other repositories prompts most developers to download their chosen packages onto their laptops, include them in their software, and run various functional tests. However, with the 1300% growth in malicious open source packages in the last two years, repositories like NuGet are increasingly hosting malicious and suspicious packages that can fool developers.

Earlier this year, RL announced the Spectra Assure Community, the largest free community resource for vetting open source software packages in npm, PyPi, and RubyGems repositories. Its simple search interface enables users to quickly check real-time risk assessment summaries before choosing or updating open source packages. The community site keeps track of more than 50,000 unique malicious packages, of which more than 5,000 were first reported by the RL research team. Threat intelligence found on this website is shared with the open source community to help with removing malicious code from package repositories.

Spectra Assure Community Adds Support for NuGet Repository

The Spectra Assure Community now includes more than 400,000 unique packages on the NuGet repository, empowering millions of .Net developers and engineering teams to make more secure choices. In addition to open source operational risk information (e.g. number of maintainers, number of dependencies, version number, and publication date), the Spectra Assure Community also summarizes threats and risks that vulnerability scanners cannot detect (see Figure 1), such as malware, tampering and application hardening issues.

Figure 1: Spectra Assure Community empowers .Net developers to review software supply chain risks before selecting or updating NuGet dependencies in their software

The community also lists software behaviors exhibited by each package. Because the threat landscape is constantly changing, avoiding components with anomalous or uncommon behaviors can be as important as detecting known malware. For example, ReversingL complex binary analysis flagged the SqzrFramework480 package (now removed from NuGet) because it contained combinations of behaviors typically associated with malicious files. Read the full research post in the RL Blog.

Validate Safety of Open Source Updates

Software teams know tgat curation isn’t a one-and-done activity. Updates to open source software packages happen all the time. And recent attacks and business disruptions facilitated through software updates should leave no doubt that newer doesn’t always mean safer. The Spectra Assure Community covers all assessed versions of the packages and an "Issues per Version Graph" (see Figure 2) can indicate the maintainers’ diligence to improve the safety of their open source package.

Figure 2: Spectra Assure Community tracks issues across NuGet package versions which can indicate the maintainers’ diligence to improving software safety

With the Spectra Assure Community, .Net developers have more insight for finding components to deliver builds that are both on-time and safe. See RL's guided tour (view time: 60 seconds) to learn how the Spectra Assure Community helps you make the best choices for keeping your credentials, projects and end-users safe from malicious attacks.

Tags:Products & Technology

More Blog Posts

Main Story

IntroSpectra Assure Community Adds Support for NuGet RepositoryValidate Safety of Open Source Updates

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagram
jasmine noel black and white headshot
net catching fish in tank

Join the free Spectra Assure Community today to get hands-on with RL's binary analysis-based software supply chain security platform.

Keep learning

  • Get up to speed on the agentic SOC in this webinar: Autonomy, Not Autopilot: Talking Agentic SOC. Plus: Learn about the new Agentic SOC Alliance.
  • Get all of RL's malware analysis and threat hunting updates with this H1 product update post — and join the webinar to discuss what a modern SOC looks like.
  • Get on top of Malware-as-a-Service with RL's report, "Copy, Paste, Compromise: The Tale of ClickFix" — and grab the related YARA rule.
  • Learn how Gartner® named RL a supply chain security 'visionary.' Download: Gartner® Magic Quadrant™ for Software Supply Chain Security.
  • Update your understanding of the Agentic Development Security tools landscape in this webinar with Forrester Sr. Analyst Janet Worthington.
  • Take a deep dive on the state of software security with RL's Software Supply Chain Security Report 2026. Plus: See the .
Instagram
YouTubeYouTube
blueskyBluesky
the webinar discussing the findings

Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Spectra Assure Community empowers .Net developers to review software supply chain risks before selecting or updating NuGet dependencies in their software
Spectra Assure Community tracks issues across NuGet package versions which can indicate the maintainers’ diligence to improving software safety

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

Related

How to Leverage Spectra Analyze's Search for SVG AnalysisRL Malware Analysis and Threat Hunting Updates for H1 2026Hunting Device Code Phishing Pages

How to Leverage Spectra Analyze's Search for SVG Analysis

Here's how to use Spectra Analyze to hunt for malicious SVGs, from setting up queries and evaluations of samples to tips for investigation.

Learn More about How to Leverage Spectra Analyze's Search for SVG Analysis
How to Leverage Spectra Analyze's Search for SVG Analysis

RL Malware Analysis and Threat Hunting Updates for H1 2026

Spectra Detect is now Kubernetes-native. Spectra Analyze adds AI workflows for the agentic SOC. Here's everything that shipped.

Learn More about RL Malware Analysis and Threat Hunting Updates for H1 2026
RL Malware Analysis and Threat Hunting Updates for H1 2026

Hunting Device Code Phishing Pages

RL recently discovered active Microsoft 365 device code phishing. Here's a walkthrough of how our researchers found the campaign.

Learn More about Hunting Device Code Phishing Pages
Hunting Device Code Phishing Pages
Leveraging the Spectra Analyze Search Function for SVG Analysis
MATH H1 2026
Spectra Analyze in Action: Hunting Device Code Phishing Pages

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research