Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious NuGet Package Targets Sicoob Banking Credentials

Malicious NuGet Package Targets Sicoob Banking Credentials

Posted on May 29, 2026 By CWS

A fraudulent NuGet package posing as an authentic Sicoob software development kit (SDK) has been identified as exfiltrating critical banking credentials. This discovery has raised substantial alarms regarding software supply chain security within financial sectors.

Deceptive SDK Targets Brazilian Banking APIs

The deceptive package, named “Sicoob.Sdk,” was aimed at developers working with Brazil’s Sicoob banking APIs. It clandestinely collected authentication credentials during typical application processes.

Appearing on NuGet in early May 2026, the package swiftly released versions from 2.0.0 to 2.0.4 before its removal. It falsely advertised itself as a .NET 8 SDK, purporting to manage authentication, mutual TLS (mTLS), and API communications with Sicoob systems.

Hidden Data Exfiltration Mechanism

The package’s attractive positioning was due to Sicoob’s extensive user base in Brazil, drawing developers focused on financial applications. However, analysis revealed built-in data exfiltration capabilities.

The malicious package logged 484 downloads across various compromised iterations. Upon instantiation with a client ID, a PFX certificate file, and a password, it secretly read and encoded the certificate, transmitting it with the plaintext password and client ID to a Sentry endpoint.

Exploiting Trusted Telemetry Platforms

Notably, the attack utilized legitimate telemetry infrastructure. Instead of traditional command-and-control servers, the SDK exploited Sentry, a reputable error monitoring platform, to transmit stolen data, blending with standard application telemetry.

Static and dynamic analyses verified that the exfiltration occurred during typical SDK initialization. Hardcoded Sentry configurations sent captured credentials as telemetry messages, occasionally including financial transaction data like boleto payment responses.

Indicators of a Supply Chain Spoofing Attack

Multiple trust red flags were evident, including the absence of stars, releases, or established activity on the public GitHub repository linked to the SDK. This mismatch pointed to a deliberate supply-chain attack with a benign-looking codebase serving as a cover for a tampered binary on NuGet.

The malicious conduct extended beyond a single package. The publisher’s account hosted numerous Sicoob-branded packages, all claiming to be official. Despite only the main SDK exhibiting confirmed malicious behavior, all related packages are deemed untrustworthy due to their shared origin.

Potential Impacts and Remediation Efforts

The breach’s consequences could be severe. By leveraging stolen credentials, attackers might access banking APIs, retrieve account data, initiate transactions, or exploit payment systems like Pix and boleto. CI/CD pipelines and production environments face increased risk, as they frequently manage real credentials.

Security experts have reported the issue to NuGet, Sentry, and Sicoob, leading to swift remedial actions, including package removal. Organizations affected are advised to rotate credentials, revoke certificates, and scrutinize API activity for suspicious access.

This incident underscores the escalating complexity of software supply chain attacks, particularly in financial services, where trusted developer tools can become potent vectors for credential theft.

Cyber Security News Tags:banking credentials, credential theft, Cybersecurity, data exfiltration, financial APIs, NuGet, security breach, Sicoob, software supply chain, Telemetry

Post navigation

Previous Post: ChatGPhish: Exploiting AI Web Summaries for Phishing
Next Post: Malicious npm Packages Compromise Developer Systems

Related Posts

PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation PoC Exploit Released for Linux-PAM Vulnerability Allowing Root Privilege Escalation Cyber Security News
IT Giant Ingram Micro Restores Operations Following Ransomware Attack IT Giant Ingram Micro Restores Operations Following Ransomware Attack Cyber Security News
Chollima Hackers Exploit PHP Developers via Packagist Chollima Hackers Exploit PHP Developers via Packagist Cyber Security News
7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code 7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code Cyber Security News
Vulnerability in TP-Link Kasa Devices Exposes Security Risks Vulnerability in TP-Link Kasa Devices Exposes Security Risks Cyber Security News
Cybercriminals Exploit Google Services in Facebook Phishing Cybercriminals Exploit Google Services in Facebook Phishing Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected
  • Hackers Use Evolving Phishing Code to Evade Detection
  • Critical ownCloud Vulnerability Used in Targeted Attacks
  • AI Systems Under Siege: RCE and API Key Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected
  • Hackers Use Evolving Phishing Code to Evade Detection
  • Critical ownCloud Vulnerability Used in Targeted Attacks
  • AI Systems Under Siege: RCE and API Key Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark