Security researchers at Socket identified a malicious NuGet package named 'Netherеum.All' that impersonated the legitimate Nethereum library by using a Cyrillic 'e' in its name, making it visually indistinguishable from the original. The package was designed to exfiltrate sensitive wallet information, including mnemonics, private keys, keystore JSON, and signed transaction data, by sending it to a command and control server themed after Solana. The threat actor leveraged the popularity of Nethereum, a widely used .NET library for Ethereum, to target developers and users in the cryptocurrency ecosystem.
The malicious package was first published on October 16, 2025, and was reported to the NuGet security team two days later, leading to its removal and the suspension of the associated publisher account. Further investigation linked this campaign to a previous typosquat, 'NethereumNet', which used similar exfiltration techniques and was also removed by NuGet. The attack highlights the risks of homoglyph abuse in package registries and the ongoing threat of supply chain attacks targeting cryptocurrency-related software.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Public reporting revealed that the malicious package, including the typosquatted name "Netherеum.All," exfiltrated stolen wallet keys through a Solana-themed command-and-control mechanism. This added technical detail clarified the package's impersonation and data theft behavior.
Socket discovered a malicious NuGet package, reported as a typosquat of the legitimate Nethereum library, designed to target developers and cryptocurrency wallet users. The package was described as attempting to steal wallet keys from affected systems.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.