Close Menu
AndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates
    What's Hot

    Google’s November Gemini Drop adds Gemini 3, Nano Banana Pro, and more

    November 22, 2025

    Black Friday: refurbished iPhone 15, 14 and 13 offers, also the iPhone 16e

    November 22, 2025

    40 Techy Gifts Under $100 That We Tested and Love

    November 22, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Google’s November Gemini Drop adds Gemini 3, Nano Banana Pro, and more
    • Black Friday: refurbished iPhone 15, 14 and 13 offers, also the iPhone 16e
    • 40 Techy Gifts Under $100 That We Tested and Love
    • Israel launches fresh wave of deadly air strikes across Gaza | Gaza
    • What Gemini features you get with Google AI Pro [Nov 2025]
    • Pamper your Switch 2 with a 25% discount on storage upgrade — save up to $25 on Samsung P9 microSD Express cards
    • Forestrike review: it trained me to become an incredible pixelated fighter
    • I found the best early Black Friday streaming service and device deals
    Saturday, November 22
    AndroidTelecom – Latest Android News, Reviews, Apps & Tech UpdatesAndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates
    • Home
    • Apps
    • Gadgets
    • News
    • Phones
    • Reviews
    • Technology
    • Tips
    • Updates
    AndroidTelecom – Latest Android News, Reviews, Apps & Tech Updates
    Home»Gadgets»Industrial computing systems at risk from “time bombs ” in malicious NuGet packages
    Gadgets

    Industrial computing systems at risk from “time bombs ” in malicious NuGet packages

    adminBy adminNovember 10, 20253 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Industrial computing systems at risk from "time bombs " in malicious NuGet packages
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • Socket found nine NuGet packages with delayed sabotage targeting industrial control systems
    • Sharp7Extend can corrupt Siemens S7 PLCs and randomly crash host processes
    • Malicious code activates in 2027–2028; users urged to audit and remove affected packages

    Thousands of critical infrastructure organizations, as well as those working in other, equally important verticals, were targeted by a perfidious attack that sought to sabotage their industrial control devices (ICD) two years down the line, experts have discovered.

    Cybersecurity researchers Socket recently found nine packages on NuGet that contained sabotage payloads set to activate in 2027 and 2028, if certain conditions were met.

    NuGet is the package manager for .NET, providing open source .NET libraries which software developers can easily integrate in their projects.


    You may like

    Thousands of victims

    According to Socket, the packages targeted all three major database providers used in .NET applications – SQL Server, PostgreSQL, and SQLite, adding that the most dangerous one is Sharp7Extend. This package targets Sharp7 library users.

    “By appending “Extend” to the trusted Sharp7 name, the threat actor exploits developers searching for Sharp7 extensions or enhancements,” Socket explained.

    The account that was hosting them is shanhai666 and, according to BleepingComputer, has had all of these delisted in the meantime. Before that happened, the packages managed to rake up almost 10,000 downloads.

    While almost all of the code in the packages (99%) was clean, that 1% could prove fatal. It was written to run whenever the app talks to databases, or Siemens S7 PLCs.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Siemens S7 industrial control devices can usually be found in manufacturing plants, energy and utilities, oil, gas, and chemical industries, building automation, and transportation.

    The payload is triggered only between August 8, 2027, and November 29, 2028, and does two destructive things: randomly kills the host process 20% of the time (causing immediate stops) and, in the Sharp7Extend package, either breaks initialization and/or, after a 90-minute delay, corrupts PLC write commands with an 80% chance.

    Who uploaded these packages and to what end, remains a mystery. Users are advised to audit their assets for the packages and remove them immediately.


    You may like

    Here is the full list of malicious packages discovered so far:

    SqlUnicorn.Core
    qlDbRepository
    SqlLiteRepository
    SqlUnicornCoreTest
    SqlUnicornCore
    SqlRepository
    MyDbRepository
    MCDbRepository
    Sharp7Extend

    Via BleepingComputer

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    bombs computing Industrial malicious NuGet packages risk systems Time
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThe Mysterious Math Behind the Brazilian Butt Lift
    Next Article Deadly blast rips through congested street near New Delhi’s Red Fort | Conflict
    admin
    • Website

    Related Posts

    Gadgets

    Pamper your Switch 2 with a 25% discount on storage upgrade — save up to $25 on Samsung P9 microSD Express cards

    November 22, 2025
    Gadgets

    Best Indoor TV Antenna (2025): Mohu, Clearstream, One for All

    November 22, 2025
    Gadgets

    In 1982, a physics joke gone wrong sparked the invention of the emoticon

    November 22, 2025
    Top Posts

    New study settles 40-year debate: Nanotyrannus is a new species

    October 30, 20253 Views

    The best early Black Friday deals we’ve found on laptops, TVs, and more

    November 15, 20252 Views

    Better Sound Than Bone Conduction—But at a Cost

    October 30, 20252 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Latest Post

    New study settles 40-year debate: Nanotyrannus is a new species

    October 30, 20253 Views

    The best early Black Friday deals we’ve found on laptops, TVs, and more

    November 15, 20252 Views

    Better Sound Than Bone Conduction—But at a Cost

    October 30, 20252 Views
    Recent Posts
    • Google’s November Gemini Drop adds Gemini 3, Nano Banana Pro, and more
    • Black Friday: refurbished iPhone 15, 14 and 13 offers, also the iPhone 16e
    • 40 Techy Gifts Under $100 That We Tested and Love
    • Israel launches fresh wave of deadly air strikes across Gaza | Gaza
    • What Gemini features you get with Google AI Pro [Nov 2025]
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 androidtelecom. Designed by .

    Type above and press Enter to search. Press Esc to cancel.