Global Conflict
SIT Reports
Public Telegram broadcast channel promoted after bounded no-media handle validation on 2026-05-31.
Original English English
🔍 Malicious NuGet Package Poses as Sicoob SDK to Steal Passwords
A fraudulent NuGet package posing as the Sicoob SDK has been identified stealing passwords. By mimicking a trusted SDK, it targets developers pulling dependencies through routine workflows.
Operationally, this highlights software supply-chain risk in the .NET ecosystem. Any environment that installed the spoofed SDK could have exposed credentials across dev machines or CI/CD. Enforce publisher verification, lock dependencies, rotate secrets, and audit recent builds.
🛰️ Open sources - closed narratives
@sitreports