Security researchers have uncovered nine malicious NuGet packages published under the alias "shanhai666" between 2023 and 2024, which contain time-delayed logic bombs designed to sabotage database operations and industrial control systems. These packages, downloaded nearly 9,500 times, appear to function as legitimate software components, implementing common patterns such as repository and unit of work, but secretly embed destructive payloads set to activate on specific dates in 2027 and 2028. The most dangerous package, Sharp7Extend, specifically targets Siemens S7 programmable logic controllers (PLCs), with mechanisms for both immediate random process termination and delayed silent write failures that can compromise safety-critical manufacturing environments.
The malicious code is carefully concealed within otherwise functional packages, making detection difficult and allowing the threat actor to build trust among developers. The payloads are triggered either probabilistically on each database query or after a set period post-installation, causing application crashes or data corruption that may be mistaken for random bugs. All identified packages have been reported to NuGet, and while some have been removed, others remained available at the time of reporting. The incident highlights the growing risk of sophisticated supply chain attacks leveraging widely used open-source repositories to target both IT and operational technology environments.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
Following Socket's findings, NuGet worked with the researchers to take down the nine malicious packages from the repository and organizations were urged to audit dependencies and assume compromise if the packages were present.
Analysis showed the most dangerous package, Sharp7Extend, specifically targeted Siemens S7 PLCs by causing random process termination and delayed write failures, creating potential safety risks in manufacturing environments.
Socket's Threat Research Team discovered that the packages contained hidden, time-delayed and probabilistic logic bombs designed to sabotage database operations and industrial control system workflows, with some triggers set years in the future.
Before they were removed, the nine packages were downloaded about 9,488 times, increasing the potential impact across database-backed applications and industrial environments.
Between 2023 and 2024, a threat actor using the alias 'shanhai666' published nine malicious NuGet packages that masqueraded as legitimate .NET libraries using typosquatting, forged metadata, and large amounts of benign code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.