Socket flags malicious NuGet packages set to activate in 2027 and 2028
Two years ago, an account with the name "shanhai666" uploaded nine malicious NuGet packages. This launched a complicated software supply-chain attack. According to supply-chain security firm Socket, the packages have been collectively downloaded 9,488 times. In addition, specific triggers are set for August 2027 and November 2028. Socket's team member, Kush Pandya, discovered the threat [...]