Cybersecurity researchers discovered a malicious NuGet package named Sicoob.Sdk that impersonates a legitimate Brazilian banking tool to steal sensitive PFX certificates and client IDs from unsuspecting software developers.
Key Points
- The malicious package, versions 2.0.0 through 2.0.4, was downloaded nearly 500 times before being blocked by NuGet.
- Attackers used the package to exfiltrate PFX certificates, passwords, and Boleto API transaction data to a hardcoded Sentry endpoint.
- Google Search AI Mode inadvertently amplified the threat by surfacing the malicious package as a legitimate C# library for Sicoob banking APIs.
- The threat actor behind the "sicoob" profile published 11 other packages, totaling approximately 6,000 downloads across the ecosystem.
- Affected organizations are advised to rotate all PFX credentials and audit API logs for unauthorized access or unusual activity.