Typosquatting 2023-2025 Incident #31

NuGet malware campaigns

Estimated Financial Impact
$10-100M+ if time bombs trigger
Blast Radius
Logic bombs set for 2027-2028; industrial PLC targeting

What Happened

Multiple campaigns targeted the .NET NuGet ecosystem including 700+ malicious packages exploiting MSBuild integrations. Most dangerous: time-bomb packages set to detonate in 2027–2028 targeting industrial PLCs with dual sabotage — random process termination and silent write failures in manufacturing. The 20% probabilistic execution makes forensic detection nearly impossible.

✓

Risk Guard: Caught

PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package

Risk Guard Check Codes That Flag This Incident

PACKAGE_NAME_MISMATCHPACKAGE_INSTALL_SCRIPTS

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_NAME_MISMATCH detects naming deviation from legitimate package
Socket Caught Typosquatting detection across ecosystems
Snyk Missed No typosquatting detection
Sonatype (Nexus) Caught Nexus Firewall typosquatting detection
Black Duck Missed No typosquatting detection
Endor Labs Missed No typosquatting detection
← @typescript_eslinter scope spoof MUT-8694 cross-ecosystem →