Industrial computer systems at risk of “time bombs” in malicious NuGet packages


  • Socket found nine NuGet packages with delayed sabotage targeting industrial control systems
  • Sharp7Extend can destroy Siemens S7 PLCs and randomly crash host processes
  • Malicious code is activated in 2027-2028; users are encouraged to review and remove affected packages

Thousands of critical infrastructure organizations, as well as those working in other, equally important verticals, were hit by a treacherous attack that attempted to sabotage their industrial control units (ICD) two years later, experts have discovered.

Cybersecurity researchers Socket recently found nine packages on NuGet that contained sabotage payloads to be activated in 2027 and 2028 if certain conditions were met.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top