AUTO-UPDATED

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Cybersecurity researchers discovered a malicious NuGet package named Sicoob.Sdk that impersonates a legitimate Brazilian banking tool to steal sensitive PFX certificates and client IDs from unsuspecting software developers.

Key Points

  • The malicious package, versions 2.0.0 through 2.0.4, was downloaded nearly 500 times before being blocked by NuGet.
  • Attackers used the package to exfiltrate PFX certificates, passwords, and Boleto API transaction data to a hardcoded Sentry endpoint.
  • Google Search AI Mode inadvertently amplified the threat by surfacing the malicious package as a legitimate C# library for Sicoob banking APIs.
  • The threat actor behind the "sicoob" profile published 11 other packages, totaling approximately 6,000 downloads across the ecosystem.
  • Affected organizations are advised to rotate all PFX credentials and audit API logs for unauthorized access or unusual activity.

Why it Matters

This incident highlights the growing danger of "manufactured legitimacy," where attackers create convincing packages that bypass traditional security filters and developer scrutiny. Such supply chain compromises can lead to widespread financial fraud and the unauthorized exposure of sensitive corporate banking data.
Internet Published by info@thehackernews.com (The Hacker News)
Read original