Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

Posted on November 7, 2025November 7, 2025 By CWS

Nov 07, 2025Ravie LakshmananSupply Chain Assault / Malware
A set of 9 malicious NuGet packages has been recognized as able to dropping time-delayed payloads to sabotage database operations and corrupt industrial management techniques.
Based on software program provide chain safety firm Socket, the packages have been revealed in 2023 and 2024 by a person named “shanhai666” and are designed to run malicious code after particular set off dates in August 2027 and November 2028. The packages have been collectively downloaded 9,488 instances.
“Essentially the most harmful bundle, Sharp7Extend, targets industrial PLCs with twin sabotage mechanisms: quick random course of termination and silent write failures that start 30-90 minutes after set up, affecting safety-critical techniques in manufacturing environments,” safety researcher Kush Pandya stated.

The checklist of malicious packages is under –

MyDbRepository (Final up to date on Could 13, 2023)
MCDbRepository (Final up to date on June 5, 2024)
Sharp7Extend (Final up to date on August 14, 2024)
SqlDbRepository (Final up to date on October 24, 2024)
SqlRepository (Final up to date on October 25, 2024)
SqlUnicornCoreTest (Final up to date on October 26, 2024)
SqlUnicornCore (Final up to date on October 26, 2024)
SqlUnicorn.Core (Final up to date on October 27, 2024)
SqlLiteRepository (Final up to date on October 28, 2024)

Socket stated all 9 rogue packages work as marketed, permitting the risk actors to construct belief amongst downstream builders who could find yourself downloading them with out realizing they arrive embedded with a logic bomb inside that is scheduled to detonate sooner or later.
The risk actor has been discovered to publish a complete of 12 packages, with the remaining three working as meant with none malicious performance. All of them have been faraway from NuGet. Sharp7Extend, the corporate added, is designed to focus on customers of the legit Sharp7 library, a .NET implementation for speaking with Siemens S7 programmable logic controllers (PLCs).
Whereas bundling Sharp7 into the NuGet bundle lends it a false sense of safety, it belies the truth that the library stealthily injects malicious code when an utility performs a database question or PLC operation by exploiting C# extension strategies.

“Extension strategies permit builders so as to add new strategies to current varieties with out modifying the unique code – a robust C# function that the risk actor weaponizes for interception,” Pandya defined. “Every time an utility executes a database question or PLC operation, these extension strategies routinely execute, checking the present date in opposition to set off dates (hardcoded in most packages, encrypted configuration in Sharp7Extend).”
As soon as a set off date is handed, the malware terminates your entire utility course of with a 20% chance. Within the case of Sharp7Extend, the malicious logic is activated instantly following set up and continues till June 6, 2028, when the termination mechanism stops by itself.
The bundle additionally features a function to sabotage write operations to the PLC 80% of the time after a randomized delay of anyplace between 30 to 90 minutes. This additionally signifies that each the triggers – the random course of terminations and write failures – are operational in tandem as soon as the grace interval elapses.

Sure SQL Server, PostgreSQL, and SQLite implementations related to different packages, alternatively, are set to set off on August 8, 2027, (MCDbRepository) and November 29, 2028 (SqlUnicornCoreTest and SqlUnicornCore).
“This staggered method offers the risk actor an extended window to gather victims earlier than the delayed-activation malware triggers, whereas instantly disrupting industrial management techniques,” Pandya stated.
It is at the moment not identified who’s behind the provision chain assault, however Socket stated supply code evaluation and the selection of the identify “shanhai666” counsel that it could be the work of a risk actor, probably of Chinese language origin.
“This marketing campaign demonstrates subtle strategies not often mixed in NuGet provide chain assaults,” the corporate concluded. “Builders who put in packages in 2024 can have moved to different tasks or firms by 2027-2028 when the database malware triggers, and the 20% probabilistic execution disguises systematic assaults as random crashes or {hardware} failures.”
“This makes incident response and forensic investigation almost not possible, organizations can not hint the malware again to its introduction level, determine who put in the compromised dependency, or set up a transparent timeline of compromise, successfully erasing the assault’s paper path.”

The Hacker News Tags:Bombs, Detonate, Hidden, Installation, Logic, MalwareLaced, NuGet, Packages, Set, Years

Post navigation

Previous Post: Chinese Hackers Organization Influence U.S. Government Policy on International Issues
Next Post: New Phising Attack Targeting Travellers from Hotel’s Compromised Booking.com Account

Related Posts

JINX-0164 Hits Crypto Firms with Sophisticated MacOS Malware JINX-0164 Hits Crypto Firms with Sophisticated MacOS Malware The Hacker News
Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild Microsoft Patches 67 Vulnerabilities Including WEBDAV Zero-Day Exploited in the Wild The Hacker News
Critical Drupal Flaw Threatens PostgreSQL Sites with RCE Critical Drupal Flaw Threatens PostgreSQL Sites with RCE The Hacker News
Why 2026 Will be the Year of Machine-Speed Security Why 2026 Will be the Year of Machine-Speed Security The Hacker News
15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign 15,000 Fake TikTok Shop Domains Deliver Malware, Steal Crypto via AI-Driven Scam Campaign The Hacker News
UNC3753 Exploits Vishing and Physical Access in U.S. Extortion UNC3753 Exploits Vishing and Physical Access in U.S. Extortion The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Scam Alert to Enhance User Safety
  • Lazarus Exploits Windows Flaw to Deploy New Backdoor
  • AI-Powered Cyberattack Targets Taiwan Government
  • Ivanti EPM Update Resolves Critical Security Flaws
  • Adobe ColdFusion Flaws Pose Severe Security Risks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark