shanhai666 is the alias used in a malicious software supply chain campaign on NuGet in which 12 .NET packages were published during 2023 and 2024, nine of them containing hidden destructive functionality. The packages were designed to appear useful and largely legitimate, with malicious logic embedded in a small portion of otherwise functional code to build trust and evade review. The campaign used typosquatting and masquerading, including a package imitating the legitimate Sharp7 ecosystem, and leveraged C# extension methods to transparently hijack database and industrial-control operations. The actor’s tooling targeted .NET database providers for SQL Server, PostgreSQL, and SQLite, as well as Siemens S7 programmable logic controller communications used in industrial environments. The database-focused packages embedded time-delayed logic bombs configured to activate years after installation, after which application processes could be terminated probabilistically during routine database operations. The PLC-focused package implemented immediate and delayed sabotage behaviors, including random host-process termination and silent failure of write operations after a grace period, creating conditions consistent with intermittent faults, data corruption, and operational disruption in safety-critical environments. The campaign demonstrates a high degree of defense evasion and post-compromise planning through delayed activation, probabilistic execution, extensive benign code cover, and metadata manipulation intended to reduce scrutiny and complicate attribution and incident response. The actor’s activity is best characterized as a destructive supply chain threat with capabilities spanning initial access through poisoned dependencies, defense evasion, persistence within software supply chains, and destructive post-exploitation effects against downstream developer and operational technology environments. Attribution to a nation state or a specific country is not supported at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
shanhai666 is responsible for publishing malicious NuGet packages, including Sharp7Extend and several database-related packages, designed to sabotage systems in the future. The packages are crafted to appear legitimate, with most code being benign, and contain destructive payloads set to trigger years after installation, targeting manufacturing and other critical environments.
The threat actor published malicious NuGet packages containing time-delayed logic bombs designed to sabotage database operations and corrupt industrial control systems, particularly targeting manufacturing environments using Siemens S7 PLCs. The attack uses sophisticated techniques such as C# extension method abuse, probabilistic process termination, and delayed activation to evade detection and complicate incident response.
The threat actor published nine malicious NuGet packages under the alias shanhai666, targeting .NET developers and industrial control systems. The packages use time-delayed, probabilistic destructive payloads to terminate host applications and silently sabotage PLC write operations, especially in manufacturing environments. The campaign leverages typosquatting, extensive legitimate code, and sophisticated evasion techniques to maximize impact and evade detection.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.