Same alias different author names, and forged signature for various packages | Image: Socket
A sophisticated supply-chain attack has been uncovered in the NuGet package registry, where nine packages published under the alias shanhai666 are designed to execute destructive, time-delayed payloads against database applications and industrial control systems. Socket’s Threat Research Team identified the packages, which were published between 2023 and 2024 and have accumulated 9,488 downloads.
Each malicious package in the campaign provides nearly all of its advertised functionality, blending genuine code with hidden sabotage. Socketβs analysis revealed that 99% of the codebase was legitimate, implementing well-known enterprise patterns like Repository, Unit of Work, and ORM reflection mapping.
βThis legitimate functionality serves multiple purposes: it builds trust as packages work as advertised, passes code reviews where reviewers see familiar patterns and real implementations, provides actual value encouraging adoption, masks the ~20-line malicious payload buried in thousands of lines of legitimate code, and delays discovery.β
The result is that these packages appear professional, functional, and reliable β until they suddenly destroy themselves or silently sabotage data integrity.
At the technical core of the campaign is an extension method injection pattern, where the attacker leverages C# extension methods to inject malicious logic into existing APIs.
βThe malware exploits C# extension methods to transparently inject malicious logic into every database and PLC operation,β Socket explained. βExtension methods allow developers to add new methods to existing types without modifying the original code β a powerful C# feature that the threat actor weaponizes for interception.β
Two methods, .Exec() for database operations and .BeginTran() for PLC communications, were added across all malicious packages. These methods appear benign but contain conditional triggers that can terminate applications or corrupt data based on specific dates and probabilities.
Socket researchers found that most malicious packages include hardcoded trigger datesβsuch as August 8, 2027 and November 29, 2028βafter which they begin terminating host processes at random.
βEach time an application executes a database query or PLC operation, these extension methods automatically executeβ¦ After the trigger date passes, the malware generates a random number between 1 and 100. If the number exceeds 80βa 20% probabilityβthe malware calls Process.GetCurrentProcess().Kill(), immediately terminating the entire application.β
Although a 20% trigger rate sounds low, Socket notes that applications making hundreds of database calls per minute will crash almost immediately once the date condition is met. For high-throughput systems, this equates to total service disruption in seconds.
βProduction applications executing hundreds of queries per hour will crash within seconds,β the report warned.
- βE-commerceΒ (100 queries/min): ~3 seconds β mid-checkout failures
- HealthcareΒ (50 queries/min): ~6 seconds β critical system outages
- FinancialΒ (500 queries/min): <1 second β complete platform failure
- Manufacturing (10 ops/min, Sharp7Extend): ~30 seconds β production crashes plus 80% silent write failures compromising safety systemsβ
The most sophisticated package, Sharp7Extend, targets industrial automation systems by mimicking a legitimate .NET library for Siemens S7 programmable logic controllers (PLCs).
βThe Sharp7Extend package specifically targets users of the legitimate Sharp7 libraryβ¦ By appending βExtendβ to the trusted Sharp7 name, the threat actor exploits developers searching for Sharp7 extensions or enhancements.β
To conceal its malicious intent, Sharp7Extend bundles the real Sharp7 library (version 1.1.79) alongside its own malicious code. This ensures that all standard PLC communications work perfectly during testingβwhile the hidden extensions quietly prepare to attack.
Socket identified two destructive mechanisms in Sharp7Extend:
- Random Process Termination β The malware terminates the process with 20% probability on every PLC connection until June 6, 2028.
- Silent Data Corruption β After a 30β90 minute grace period, the package begins causing 80% of write operations to fail silently.
This two-phase sabotage makes debugging extremely difficult. Initial crashes seem random, while subsequent data corruption appears as βhardware faults,β allowing the malware to persist undetected in production environments.
To increase adoption, the shanhai666 actor also published three legitimate packages alongside the nine malicious ones to build a history of credible contributions on NuGet.
βDevelopers researching the author find genuine, working packages alongside the malicious ones, reducing suspicion,β Socket noted. βThe malicious packages strategically target all three major database providers used in .NET applications β SQL Server, PostgreSQL, SQLite β plus industrial control systems.β
The attacker even forged .nuspec author fields to display different names across packages, a tactic to evade reputation-based security scanning.
Several clues point toward a possible Chinese origin for the campaign. Socketβs analysis revealed Chinese-language comments embedded in the DLLs, such as βεΊη°εΌεΈΈβ (exception occurred) and βθΏζ₯ε€±θ΄₯β (connection failed). The alias βshanhai666β itself appears to derive from Chinese, translating to βmountains and seasβ, with β666β being Chinese internet slang for βexcellentβ or βsmooth.β
Socket has reported all malicious packages to NuGet, which confirmed that it is investigating and working on removal. However, as of Socketβs publication, the packages remained live on the registry.
Related Posts:
- Malicious NuGet Campaign Exploits Homoglyphs and Code Injection to Fool Developers
- NuGet’s Stealth Malware: The Hidden SeroXen RAT Threat
- Socket Uncovers Malicious NuGet Typosquat βNetherΠ΅um.Allβ Exfiltrating Wallet Keys via Solana-Themed C2
- Conti ransomware source code leaks
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!