Multiple campaigns targeted the .NET NuGet ecosystem including 700+ malicious packages exploiting MSBuild integrations. Most dangerous: time-bomb packages set to detonate in 2027–2028 targeting industrial PLCs with dual sabotage — random process termination and silent write failures in manufacturing. The 20% probabilistic execution makes forensic detection nearly impossible.
PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package |
| Socket | Caught | Typosquatting detection across ecosystems |
| Snyk | Missed | No typosquatting detection |
| Sonatype (Nexus) | Caught | Nexus Firewall typosquatting detection |
| Black Duck | Missed | No typosquatting detection |
| Endor Labs | Missed | No typosquatting detection |