NuGet Typosquats Turn Trusted Builds Into Stealer Delivery
The problem is not just five bad packages. It is that they sit on NuGet under plausible Chinese .NET names, so normal dependency resolution can turn developer laptops and CI runners into stealer victims without any obvious compromise of the host itself.
Socket says the packages were published by bmrxntfj, impersonate widely used Chinese .NET UI and infrastructure libraries, and bundle a .NET Reactor-protected infostealer. The payload targets browser credentials, crypto wallets, SSH keys, and local files, and the five packages have together reached about 65,000 downloads.
All five packages were still available at the time of reporting. That keeps the delivery path live, and it means the main risk is not one infected workstation but any build or developer environment that already pulled the names before takedown.