[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fAm7Pu0b9gkMnWPK95UQDhdBQnRTh03SNBD0Dm2wgfO0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"004decc4-4957-4ebc-8982-3fce3cb20a0d","malicious-nuget-package-targets-banking-credentials-through-package-impersonation","5ac84b0e-5613-43ab-b1c8-ef763c3faea7","Malicious NuGet Package Targets Banking Credentials Through Package Impersonation","Attackers successfully published a fake Sicoob.Sdk NuGet package that impersonated a legitimate banking SDK to steal sensitive authentication materials including client certificates and passwords. The malicious package used a spoofed publisher identity and reached 484 downloads before detection, demonstrating how supply chain attacks can bypass traditional security controls. Organizations that downloaded the package face immediate risk of unauthorized banking API access and must take emergency remediation steps. This incident highlights the critical need for package verification processes and developer security training.","**Immediate actions:**\n- Audit all NuGet package downloads to identify if Sicoob.Sdk versions 2.0.0-2.0.4 were installed\n- Revoke and reissue all PFX certificates that may have been exposed to the malicious package\n- Review Sicoob API access logs for unauthorized transactions or suspicious activity\n\n**Long-term improvements:**\n- Implement package signature verification and trusted publisher policies for all dependency management systems\n- Establish mandatory security review processes for third-party packages before deployment\n- Deploy automated scanning tools to detect malicious packages in private repositories\n\n**Detection measures:**\n- Monitor network traffic for unexpected data exfiltration to external endpoints like Sentry\n- Set up alerts for installation of packages from unverified or newly created publishers\n- Implement certificate usage monitoring to detect unauthorized access attempts",[12,13,14,15,16,17],"CIS Control 2","CIS Control 13","NIST SP 800-161","NIST SC-29","SLSA Framework","OWASP Top 10 A06","published","2026-05-29T00:20:19.8073+00:00","2026-05-29T00:20:19.414+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fmalicious-nuget-package-impersonates-sicoob-sdk?utm_medium=feed","malicious-nuget-package-impersonates-sicoob-sdk-to-exfiltrate-banking-certificat-aebfea","Malicious NuGet Package Impersonates Sicoob SDK to Exfiltrate Banking Certificates and Passwords",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]