Moq, a super popular NuGet package, included a dependency that harvested email addresses from the git.config files of all Moq users.

The behavior was removed, but by that point, it collected quite the data.

You don't need to have malicious/shady bejavior up for months... a few days in a super-popular library and the damage is done.

https://medium.com/checkmarx-security/popular-nuget-package-moq-silently-exfiltrates-user-data-to-cloud-service-d1888867406d

Reply to this note

Please Login to reply.

Discussion

No replies yet.