Microsoft said NuGet.org will shorten the lifetime of newly created API keys from 365 days to 30 days to reduce software supply-chain risk from stolen publishing credentials. The change takes effect on August 17, 2026, and Microsoft warned that attackers who obtain long-lived keys can publish trojanized .NET packages under trusted project names, creating rapid downstream exposure for developers and enterprises.
The company also said all NuGet API keys created before that date will expire on November 1, 2026, requiring maintainers to generate new keys or migrate to NuGet Trusted Publishing. Microsoft is pushing the OIDC-based model, introduced in 2025, because it replaces reusable secrets with short-lived session credentials for workflows such as GitHub Actions and GitLab, and cited the NX Console npm package compromise as a recent example of how stolen publishing credentials can be used to poison software packages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
NuGet.org announced that all API keys created before August 17, 2026 will expire on November 1, 2026 as part of its supply-chain security changes. The move extends the API key lifetime reduction beyond newly created keys to force rotation of older long-lived publishing credentials.
Microsoft introduced NuGet Trusted Publishing in September 2025 as a keyless publishing option for NuGet.org. The feature uses OpenID Connect to authenticate publishing workflows and issue temporary session-based credentials instead of long-lived API keys.
Microsoft announced that new NuGet.org API keys will be limited to 30 days instead of 365 days to reduce supply-chain risk from stolen publishing credentials. The company also urged maintainers to adopt Trusted Publishing as a more secure alternative to reusable secrets.
Microsoft cited a recent NX Console npm package compromise in which an attacker used stolen publishing credentials to release a malicious package. According to the NX Dev Team, the malicious package was activated 6,000 times in 36 minutes before it was removed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcedevblogs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.