Industrial computing systems at risk from “time bombs ” in malicious NuGet packages

  • Socket found nine NuGet packages with delayed sabotage targeting industrial control systems
  • Sharp7Extend can corrupt Siemens S7 PLCs and randomly crash host processes
  • Malicious code activates in 2027–2028; users urged to audit and remove affected packages

Thousands of critical infrastructure organizations, as well as those working in other, equally important verticals, were targeted by a perfidious attack that sought to sabotage their industrial control devices (ICD) two years down the line, experts have discovered.

Cybersecurity researchers Socket recently found nine packages on NuGet that contained sabotage payloads set to activate in 2027 and 2028, if certain conditions were met.

NuGet is the package manager for .NET, providing open source .NET libraries which software developers can easily integrate in their projects.

Thousands of victims

According to Socket, the packages targeted all three major database providers used in .NET applications – SQL Server, PostgreSQL, and SQLite, adding that the most dangerous one is Sharp7Extend. This package targets Sharp7 library users.

“By appending “Extend” to the trusted Sharp7 name, the threat actor exploits developers searching for Sharp7 extensions or enhancements,” Socket explained.

The account that was hosting them is shanhai666 and, according to BleepingComputer, has had all of these delisted in the meantime. Before that happened, the packages managed to rake up almost 10,000 downloads.

While almost all of the code in the packages (99%) was clean, that 1% could prove fatal. It was written to run whenever the app talks to databases, or Siemens S7 PLCs.

Siemens S7 industrial control devices can usually be found in manufacturing plants, energy and utilities, oil, gas, and chemical industries, building automation, and transportation.

The payload is triggered only between August 8, 2027, and November 29, 2028, and does two destructive things: randomly kills the host process 20% of the time (causing immediate stops) and, in the Sharp7Extend package, either breaks initialization and/or, after a 90-minute delay, corrupts PLC write commands with an 80% chance.

Who uploaded these packages and to what end, remains a mystery. Users are advised to audit their assets for the packages and remove them immediately.

Here is the full list of malicious packages discovered so far:

SqlUnicorn.Core
qlDbRepository
SqlLiteRepository
SqlUnicornCoreTest
SqlUnicornCore
SqlRepository
MyDbRepository
MCDbRepository
Sharp7Extend

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

The Clapper was a bad smart home gadget — and a viral sensation

Clap on. Clap off. Well, more like, Clap, pause for half a beat but no longer because otherwise it'll stop hearing you, clap again...

US Marshals arrest the Tate brothers in Miami

Andrew and Tristan Tate talk to the media on March 23, 2025 in Romania. | Image: Andrei Pungovschi/Getty Images The manosphere influencers Andrew and Tristan...

Birdfy’s solar-powered smart feeder is down to one of its best prices

It comes with a solar panel so you don’t need to worry about charging as much during the summer. | Image: Netvue Birdfy has kicked...

Orchid is a delightfully retro and approachable hipster synth

A modern tribute to electric chord organs which were basically giant harmonicas connected to a fan. | Photo: Terrence O’Brien / The Verge In 2017,...

OnePlus died with a whimper, not a bang

OnePlus is dead – actually for real this time. It’s got me looking back on my experiences with the brand’s smartphones, the absolute roller...

The grueling, 630-mile road race where the only fuel is sunlight

The 2018 Solar Car Challenge was the last time participants took their designs out on the open road. | Image: Lehman Marks / Solar...

The future of physical games is not looking great

Grand Theft Auto VI release won’t offer a disc. | Image: Rockstar Games This is The Stepback, a weekly newsletter breaking down one essential story...

Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’

Dave Eggers attends the "The Turning Point: To Be Destroyed" premiere. | Image: John Lamparski/Getty Images for Tribeca Festival Last year, Sam Altman invited author...

YouTube picture-in-picture (PiP) mode is broken on iPhone, Android

YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app. Read more @ 9to5google

Galaxy Watch 9 is ‘Powered by Snapdragon Wear Elite,’ leaked images confirm [Gallery]

As expected, Samsung is switching its new Galaxy Watch 9 over to a Qualcomm chip, the Snapdragon Wear Elite, as some new images confirm....