{"id":1087,"date":"2026-05-29T10:42:10","date_gmt":"2026-05-29T10:42:10","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1087"},"modified":"2026-05-29T10:42:10","modified_gmt":"2026-05-29T10:42:10","slug":"malicious-sicoob-nuget-steals-banking-credentials-as-npm-packages-target-cloud-secrets","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1087","title":{"rendered":"Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgUbmZyAOVZRXrWddG8PMuXbVyex9s5HPD2cH8rDjYP6EHuVadkyj72NdN9PreAnGX9iOCVGxWI2YmSLu818VmdLGEcPkb60qPIUgBYh5oBHsA4KKYufsHbFGhAQDD7SjpZU0In0TPiHN4TxCR4THBwmKa4Bus98vBgx5mO3QTQRpTM5RERk8bFWi4psF7d\/s1700-e365\/sdk.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil&#8217;s largest cooperative financial systems, to siphon client IDs and PFX certificates.<\/p>\n<p>According to <a href=\"https:\/\/socket.dev\/blog\/malicious-nuget-package-impersonates-sicoob-sdk\">Socket<\/a>, versions 2.0.0 through 2.0.4 of \u00ab<a href=\"https:\/\/www.nuget.org\/packages\/Sicoob.Sdk\">Sicoob.Sdk<\/a>\u00bb contain functionality to exfiltrate sensitive information, including PFX certificates that are used to authenticate businesses with the Sicoob banking network in order to automate banking operations, such as processing instant payments and generating dynamic Pix QR codes. The package is estimated to have been downloaded nearly 500 times.<\/p>\n<p>\u00abWhen a developer instantiates SicoobClient with a client ID, a PFX file path, and a PFX password, the package reads the PFX file from disk, Base64-encodes its contents, and sends the supplied client ID, PFX password, and encoded PFX data to a hardcoded third-party Sentry endpoint,\u00bb security researcher Kirill Boychenko said.<\/p>\n<p>In addition, the package is designed to capture raw Boleto API responses via a separate Sentry path. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Boleto\">Boleto<\/a> is a popular cash payment method in Brazil for making online and offline purchases. This can potentially expose sensitive transaction details, payment status, amounts, due dates, identifiers, and payer or payee data.<\/p>\n<p>As a result, the stolen data could open the door to severe risks, as it can be abused by the threat actor to impersonate the victim&#8217;s Sicoob banking API integration, Socket added. Following responsible disclosure, the package has been blocked by NuGet. The profile behind the package, named \u00absicoob,\u00bb has also listed 11 other NuGet packages that have collectively racked up about 6,000 downloads.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlabz-vpn-risk-2026-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhnNON5UeWywT7OcPNw7V4L7QNWnCnm7Xl_99Y9ek8dL-gRwx-bWxQM1TKqt8deqqrdpUyKMuuijAWyyPQVB0s0qf8ntQ6ldFAJLru-QUWhddKTopc7SeNbBBnd-TsfFyRPP-AAyDuclLlL6XHK4_LXqDC_7eyaz9pzToYr7U543MhrJ7qcK-89sVWHTQUZ\/s728-e100\/zz-2-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The application security company also said the package was surfaced by Google Search AI Mode as a legitimate C# library for interacting with Sicoob banking APIs, thereby amplifying the malicious package to unsuspecting developers who may be searching for it.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Another important aspect of the attack is the source-to-package mismatch between the <a href=\"https:\/\/github.com\/Sicoob-Cooperativa\">linked GitHub repository<\/a> and the artifact distributed via NuGet. It&#8217;s suspected that the GitHub repository is designed to lend a veneer of legitimacy to the operation by keeping it clean, while the malicious data-stealing functionality is introduced only in the package uploaded to the registry.<\/p>\n<p>What&#8217;s more, the compromise of Sicoob API authentication material can also pose indirect risks to end users, as it could leak downstream financial data or enable payment abuse.<\/p>\n<p>Organizations that have installed \u00abSicoob.Sdk\u00bb are recommended to immediately remove the package, treat PFX material as compromised, replace exposed PFX certificates, rotate PFX passwords, and change or disable affected client IDs where applicable. It&#8217;s also advised to audit Sicoob authentication and API logs for signs of unusual activity.<\/p>\n<p>The development coincides with the <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/05\/28\/typosquatted-npm-packages-used-steal-cloud-ci-cd-secrets\/\">discovery<\/a> of 14 malicious npm packages that typosquat well-known OpenSearch, ElasticSearch, DevOps, and environment-configuration libraries to harvest AWS credentials, HashiCorp Vault tokens, npm tokens, and CI\/CD pipeline secrets from the host environment using a purpose-built credential harvester that&#8217;s launched through a preinstall hook.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgl8GTYDoJnPuVc-Moe3_cvURFF5ffKE6oLQpRZZSqm_CpZMnLgWPCuuRic86H7eEi9hFAU0KGwT-DiK2QS8ZAh9fwW4ioenx91SS5g8SS8l8q6FRFk9FBeZ7fnCkBw9SvmA2mz68KzSihGNHC42TdYkl7ZP0PdJsngTIq-ep2xqPCOQN7X-Dpx8EfRYp4q\/s1700-e365\/signed.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgl8GTYDoJnPuVc-Moe3_cvURFF5ffKE6oLQpRZZSqm_CpZMnLgWPCuuRic86H7eEi9hFAU0KGwT-DiK2QS8ZAh9fwW4ioenx91SS5g8SS8l8q6FRFk9FBeZ7fnCkBw9SvmA2mz68KzSihGNHC42TdYkl7ZP0PdJsngTIq-ep2xqPCOQN7X-Dpx8EfRYp4q\/s1700-e365\/signed.jpg\" alt=\"\" border=\"0\" data-original-height=\"554\" data-original-width=\"1020\"\/><\/a><\/div>\n<p>Per the Microsoft Defender Security Research Team, the packages were published by a single threat actor named \u00abvpmdhaj\u00bb (\u00aba39155771@gmail.com\u00bb) on May 28, 2026. The names of the packages are below &#8211;<\/p>\n<ul>\n<li>@vpmdhaj\/devops-tools<\/li>\n<li>@vpmdhaj\/elastic-helper<\/li>\n<li>@vpmdhaj\/opensearch-setup<\/li>\n<li>@vpmdhaj\/search-setup<\/li>\n<li>app-config-utility<\/li>\n<li>elastic-opensearch-helper<\/li>\n<li>env-config-manager<\/li>\n<li>opensearch-config-utility<\/li>\n<li>opensearch-security-scanner<\/li>\n<li>opensearch-setup<\/li>\n<li>opensearch-setup-tool<\/li>\n<li>search-cluster-setup<\/li>\n<li>search-engine-setup<\/li>\n<li>vpmdhaj-opensearch-setup<\/li>\n<\/ul>\n<p>The findings are the latest in a staggering spate of supply chain attack campaigns that have targeted the npm ecosystem over the past few days &#8211;<\/p>\n<ul>\n<li><a href=\"https:\/\/safedep.io\/oob-moika-tech-dependency-confusion-campaign\/\">164 malicious npm packages<\/a> across five scoped namespaces containing a postinstall payload that downloads second-stage JavaScript, spawns it as a detached process, and sends the victim&#8217;s environment variables (\u00abprocess.env\u00bb) to \u00aboob.moika[.]tech\/report.\u00bb<\/li>\n<li><a href=\"https:\/\/safedep.io\/malicious-npm-terminal3airport-proxy-adware-spam\/\">141 malicious npm packages<\/a> published between May 7 and 27, 2026, that abuse npm as free static hosting for an ad-monetized web proxy targeting students, serving popunder ads to those who land these pages through search results or shared links.<\/li>\n<li>A malicious npm package called \u00ab<a href=\"https:\/\/safedep.io\/malicious-forge-jsxy-npm-rat-evolution\/\">forge-jsxy<\/a>\u00bb that&#8217;s capable of keylogging, clipboard monitoring, .env scanning, shell history exfiltration, host inventory, remote filesystem access, screenshot capture, and cryptocurrency wallet scanning. \u00abForge-jsxy\u00bb is assessed to be a continuation of the \u00abforge-jsx\u00bb campaign that came to light late last month.<\/li>\n<li><a href=\"https:\/\/www.sonatype.com\/blog\/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies\">176 malicious npm packages<\/a> that employ dependency confusion by using a high version number (\u00ab99.99.99\u00bb) to distribute a postinstall script with capabilities to fingerprint the host and download a platform-specific JavaScript payload, which then conducts additional reconnaissance, exfiltrates credentials and other valuable developer secrets, and downloads and runs a second-stage binary.<\/li>\n<\/ul>\n<p>In a newly published report, Sonatype said threat actors have outgrown classic typosquatting techniques, moving beyond obvious misspellings to using names that appear convincing in legitimate developer workflows so as to steal data and drop malicious payloads. This, in turn, transforms a routine install step into a risk-prone pathway for reconnaissance, credential theft, and follow-on compromise.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Popular brandjacking techniques include prefix or suffix addition, dependency confusion, version mimicry, embedded target terms, altered scopes or namespaces, and names that resemble the function of a legitimate package.<\/p>\n<p>\u00ab&#8216;Typosquatting&#8217; is now too narrow a label for what this analysis captures,\u00bb the supply chain security company <a href=\"https:\/\/www.sonatype.com\/resources\/research\/beyond-typosquatting-attacks\">said<\/a>. \u00abThe broader pattern is manufactured legitimacy: attackers designing package names to look plausible, useful, and operationally routine inside modern software ecosystems.\u00bb<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhk0-zlLAqLaWvqiSWacN9HpghIyvXVZFH-BO2wZWBhKpY1UorsS0qIAvt19ntzvB1IAuSy52ryXsN-LVgiykn_vr7MO0MtUiCFXtc9HYBhPEzulk5PKnm6Jtm3AOCrJlhWARGTI0lvmDYlnJwWCpePWD0wBdVY_f8MpiRhRACB9vpz014BUccezUDVFfsL\/s1700-e365\/typosquatting.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhk0-zlLAqLaWvqiSWacN9HpghIyvXVZFH-BO2wZWBhKpY1UorsS0qIAvt19ntzvB1IAuSy52ryXsN-LVgiykn_vr7MO0MtUiCFXtc9HYBhPEzulk5PKnm6Jtm3AOCrJlhWARGTI0lvmDYlnJwWCpePWD0wBdVY_f8MpiRhRACB9vpz014BUccezUDVFfsL\/s1700-e365\/typosquatting.jpg\" alt=\"\" border=\"0\" data-original-height=\"755\" data-original-width=\"1300\"\/><\/a><\/div>\n<p>These incidents have also unfolded against a series of software supply chain compromises that have been linked to TeamPCP (aka Replicating Marauder and UNC6780), which has become a force to be reckoned with by poisoning popular developer tooling across npm, PyPI, Docker Hub, and Packagist in a worm-like fashion.<\/p>\n<p>\u00abReplicating Marauder was not just inserting malicious code into packages, but also exploiting automation, inherited trust, and ordinary CI\/CD workflows to push compromise further downstream,\u00bb BlueVoyant researcher Michael Warren <a href=\"https:\/\/www.bluevoyant.com\/blog\/how-replicating-marauder-rewired-the-supply-chain-playbook\">said<\/a>.<\/p>\n<p>\u00abThis was the point where the campaign most clearly demonstrated that one poisoned dependency or container image could trigger compromise in an unrelated organization&#8217;s release pipeline. The tactical shift turned isolated software poisoning into a reproducible method for victim-to-victim expansion.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil&#8217;s largest cooperative financial systems, to siphon client IDs and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1088,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[615,329,446,33,39,34,35,145,1837,295,492],"class_list":["post-1087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-banking","tag-cloud","tag-credentials","tag-malicious","tag-npm","tag-nuget","tag-packages","tag-secrets","tag-sicoob","tag-steals","tag-target"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1087"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1088"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}