Nethereum typosquatted NuGet package campaign with download inflation
Campaign
Summary
Hide ▲
Show ▼
Typosquatted NuGet uploads were used in a repeat campaign that tried to look popular enough to trick developers into installing a malicious dependency and exposing crypto wallet keys. The operation reused the same impersonation pattern across more than one package, making it an ongoing supply-chain threat rather than a one-off upload. False download counts and a counterfeit package name increased the chance of successful installs.
Related Happenings
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
Campaign
H score45
First: 12.05.2026 17:45
Last: 12.05.2026 17:45
Sources 1
About this happening:
The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
CampaignAbout this happening: The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Latest development: 21.05.2026 11:00
Grafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.
TanStack hit by network compromise
Incident
H score29
First: 12.05.2026 17:45
Last: 12.05.2026 17:45
Sources 1
About this happening:
TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release...
TanStack hit by network compromise
IncidentAbout this happening: TanStack was hit by a package compromise on May 11, 2026, when attackers published 84 malicious versions across 42 @tanstack/* packages and abused the release...
Latest development: 21.05.2026 11:00
On May 17, 2026, Grafana Labs said an unauthorized attacker had downloaded its codebase after accessing the firm's GitHub environment, and the company later said additional internal operational information and business contact names and email addresses were taken from its GitHub repositories; Grafana Labs said there was no indication that customer production systems or the Grafana Cloud platform were compromised.
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
Campaign
H score56
First: 12.05.2026 14:29
Last: 12.05.2026 14:29
Sources 1
About this happening:
GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
CampaignAbout this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Mini Shai-Hulud npm supply-chain malware wave
Malware Activity
H score68
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Mini Shai-Hulud npm supply-chain malware wave
Malware ActivityAbout this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Latest development: 09.06.2026 18:42
On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.
RoshniNaveenaS's account hit by network compromise
Incident
H score18
First: 29.04.2026 19:26
Last: 29.04.2026 19:26
Sources 1
About this happening:
The RoshniNaveenaS account was compromised, enabling attackers to publish malicious @cap-js releases without provenance and putting downstream npm consumers at ris...
RoshniNaveenaS's account hit by network compromise
IncidentAbout this happening: The RoshniNaveenaS account was compromised, enabling attackers to publish malicious @cap-js releases without provenance and putting downstream npm consumers at ris...
Timeline
-
22.10.2025 14:43 1 articles · 8mo ago
Netherеum.All typosquat uploaded to NuGet
Campaign Scope UpdateA malicious NuGet package named Netherеum.All was uploaded by the user "nethereumgroup" to impersonate Nethereum with a Cyrillic homoglyph swap in the package name, inflate its apparent popularity to 11.7 million downloads, and deliver code that decoded the C2 endpoint solananetworkinstance[.]info/api/gads to exfiltrate mnemonic phrases, private keys, and keystore data.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
-
22.10.2025 14:43 1 articles · 8mo ago
NuGet removes malicious Netherеum.All package
Mitigation Patch UpdateNuGet removed Netherеum.All for violating the service's Terms of Use four days after the upload, cutting off the malicious typosquat that targeted Nethereum users and sought cryptocurrency wallet keys.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
-
22.10.2025 14:43 2 articles · 8mo ago
Researchers disclose Nethereum NuGet typosquat campaign
Initial DisclosureSecurity researchers disclosed a NuGet supply chain campaign against Nethereum users, noting that the same deceptive functionality had already appeared in NethereumNet at the start of October 2025 and that NuGet's permissive naming rules can make homoglyph typosquats easier to publish.
Show sources
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43
- Fake Nethereum NuGet Package Used Homoglyph Trick to Steal Crypto Wallet Keys — thehackernews.com — 22.10.2025 14:43