fromThe Hacker News
4 hours agoHidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation
According to software supply chain security company Socket, the packages were published in 2023 and 2024 by a user named " shanhai666" and are designed to run malicious code after specific trigger dates in August 2027 and November 2028. The packages were collectively downloaded 9,488 times. "The most dangerous package, Sharp7Extend, targets industrial PLCs with dual sabotage mechanisms: immediate random process termination and silent write failures that begin 30-90 minutes after installation, affecting safety-critical systems in manufacturing environments," security researcher Kush Pandya said.
Information security











.jpg?height=635&t=1757344641&width=1200)










