(Is TJ a #god ?
.How do you even spot this ?! )
https://m.youtube.com/watch?v=g2DO2Xhccq8
#repost •acws #acws
#nuget #anthrax #AppLocker #seroXen
.These packages, spanning various versions, mimic popular packages and exploit NuGet’s MSBuild integrations feature to insert malicious code into their targets.
Cybersecurity researchers have uncovered a novel collection of malicious packages that were surreptitiously uploaded to the NuGet package manager using an unconventional method for deploying malwar…
#Nuget packages aren't immune to software supply chain attacks! Phylum has uncovered several packages delivering the #seroxen RAT 🐀
#malware #supplychain #opensource #infosec #csharp #cybersecurity
https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/
On October 6, 2023, Phylum’s automated risk detection platform alerted us to a suspicious publication on NuGet. After working through several layers of obfuscation we ultimately discovered that this package was delivering SeroXen RAT. Background The package in question is Pathoschild.Stardew.Mod.Build.Config published by a user