Eleven malicious NuGet packages posing as game cheats, utility panels, and a calculator-themed tool were used in a supply-chain campaign to infect Windows systems with a payload named pepesoft.exe. The packages were published as .NET command-line tools, so the infection chain could begin when a user installed and ran the tool, triggering a .NET downloader that retrieved a second-stage Python payload packaged with PyInstaller.
The malware infrastructure relied on legitimate services including GitHub Releases, Hugging Face, Google DNS, and Google Sheets under activity linked to the username pepegit666, helping the traffic blend in with normal enterprise use. Reported capabilities included hardware fingerprinting, cloud-based configuration retrieval, Google Sheets-backed telemetry and licensing checks, remote ban lists, and in some variants Telegram-based screenshot capture; defenders are advised to treat affected hosts as fully exposed and rotate credentials from a clean device.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Analysis found the .NET downloader fetched a second-stage PyInstaller-packed Python payload from GitHub Releases or Hugging Face infrastructure associated with the username pepegit666. Reported capabilities included hardware fingerprinting, Google Sheets-based telemetry and licensing, remote ban lists, cloud configuration retrieval, and Telegram-based screenshot capture in some builds.
Socket analyzed a supply-chain campaign involving 11 malicious NuGet packages masquerading as game utilities, cheat panels, and a calculator-themed tool. The packages were published as .NET command-line tools that executed a downloader chain when installed and run.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcetrojan-killer.net
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.