ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

New Wave of Malicious NuGet Packages Impacts .NET Developers

The malware found deployed goes by the name "SeroXen RAT"

Kyle by Kyle
October 31, 2023
in Malware
Reading Time: 2 mins read
SeroXen RAT infects .NET Nuget Packages
Share on FacebookShare on Twitter

In a recent discovery, cybersecurity researchers have exposed a coordinated and ongoing campaign targeting the NuGet package manager.

Initiated on August 1, 2023, this campaign, linked to a slew of rogue NuGet packages, has been delivering a remote access trojan known as SeroXen RAT, according to software supply chain security firm ReversingLabs.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Karlo Zanki, a reverse engineer at ReversingLabs, described the threat actors as persistent in their quest to introduce malware into the NuGet repository and continuously release new malicious packages.

SeroXen RAT Spread Via NuGet Packages
The snippet of code that is downloading an executing SeroXen RAT. Credit: Reversing Labs

Some of the deceptive package names involved in this campaign include:

  • Pathoschild.Stardew.Mod.Build.Config
  • KucoinExchange.Net
  • Kraken.Exchange
  • DiscordsRpc
  • SolanaWallet
  • Monero
  • Modern.Winform.UI
  • MinecraftPocket.Server
  • IAmRoot
  • ZendeskApi.Client.V2
  • Betalgo.Open.AI
  • Forge.Open.AI
  • Pathoschild.Stardew.Mod.BuildConfig
  • CData.NetSuite.Net.Framework
  • CData.Salesforce.Net.Framework
  • CData.Snowflake.API

These packages span multiple versions and imitate well-known packages. The attackers leverage NuGet’s MSBuild integrations feature to insert malicious code into their victims’ systems, using inline tasks to execute code. Notably, this marks the first instance of malware infiltrating the NuGet repository by exploiting the inline tasks feature for malware execution.

The recently removed packages share common characteristics, with threat actors striving to conceal the malicious code by using spaces and tabs to keep it out of the default screen view. Additionally, the packages artificially inflate their download counts to create an illusion of legitimacy. Their primary objective is to serve as a conduit for fetching a second-stage .NET payload hosted on a temporary GitHub repository.

Karlo Zanki emphasized that the threat actor behind this campaign is meticulous and detail-oriented, demonstrating a commitment to sustaining this malicious operation.

Tags: SeroXen RAT
Previous Post

North Korean State-Backed Hackers Utilize Known Software Vulnerabilities

Next Post

Unprecedented Cyber Breach via MOVEit Software Rattles Multiple Sectors

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.