Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
EXPIRED
53.5
2026-05-30T07:00
Score-Aufschlüsselung
100
novelty
25
reach
35
concrete_impact
55
emotional_hook
70
source_quality
45
platform_fit
Zusammenfassung
Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of "Sicoob.Sdk" contain functionality to exfiltrate sensitive information, including PFX certificates that are used to
Skripte (0)
d4a73c9d…
Noch kein Skript generiert.
Score 53.5 — unter Schwellwert (65)