Five malicious NuGet packages have been discovered targeting .NET developers by stealing browser credentials, SSH keys, and cryptocurrency wallet data. These rogue packages mimic legitimate Chinese software libraries to evade detection, posing a significant risk to developer workstations and CI/CD systems with tens of thousands of downloads since September 2025. Developers must urgently check for these packages in their projects and rotate affected credentials and keys.
Read the full article at Cyber Security News
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



