Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Malicious NuGet packages linked to industrial espionage target developers
    Cyber Security

    Malicious NuGet packages linked to industrial espionage target developers

    techempireBy techempire3 Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 26, 2024Editorial DepartmentIndustrial espionage/threat intelligence

    Malicious NuGet suite

    Threat trackers have discovered a suspicious kit in the NuGet Kit Manager that may be designed to target developers using tools made by Chinese companies specializing in industrial and digital device manufacturing.

    The bag in question is Sqzr Framework 480, ReversingLabs stated that this article was first published on January 24, 2024. As of this writing, the article has been downloaded 2,999 times.

    The software supply chain security company said it is not aware of any other software packages exhibiting similar behavior.

    However, it speculates that the campaign is likely to be used to orchestrate industrial espionage on systems equipped with cameras, machine vision and robotic arms.

    Internet security

    SqzrFramework480 appears to be connected to a Chinese company called Bozhong Precision Industrial Technology Co., Ltd. This indication comes from the use of a version of the company’s logo in the packaging icon. It was uploaded by a Nuget user account named “zhaoyushun1999”.

    There is a DLL file “SqzrFramework480.dll” in the library. This file has the function of taking screenshots and pinging the remote IP address every 30 seconds until the operation is successful. Transfer screenshots.

    “None of these actions are absolutely malicious. However, when combined, they raise alarms,” ​​said security researcher Petar Kirhmajer. “The ping acts as a heartbeat check to see if the penetration server is active.”

    Malicious NuGet suite

    Malicious use of sockets for data communication and exfiltration has previously been observed in the wild, such as in the case of the npm package nodejs_net_server.

    The exact motivation behind this package is unclear, but it is known that adversaries are constantly harming victims by hiding malicious code in seemingly benign software.

    Internet security

    Another harmless explanation could be that the package was leaked by a developer or a third party working with the company.

    “They may also explain the seemingly malicious continuous screen capture behavior: it may just be a way for developers to transfer camera footage from the main monitor to a workstation,” Kirhmajer said.

    In addition to the ambiguity surrounding the package, the findings underscore the complexity of the supply chain threat and the need for users to double-check the library before downloading it.

    “Open source repositories like NuGet are increasingly hosting suspicious malware packages designed to attract developers and trick them into downloading malicious libraries and other mods and incorporating them into their development pipelines,” Kirhmajer said.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.