Feed
HighPublished 20 Jul 2026174 packages · 0 versions

GitHub Advisory backfill sweep — ~264 NuGet CWE-506 malware advisories dominated by Solana wallet impersonators, WPF/WinForms UI-kit typosquats, and popular-API impersonators (Zendesk, Binance, Coinbase, Ripple, Stripe, PayPal, Kraken, Kucoin, Huobi, Bybit)

Summary

On 2026-07-20 GitHub's Advisory Database published a ~264-package NuGet CWE-506 malware backfill — the largest single-day NuGet sweep on record. Dominant themes: Solana/crypto wallet impersonators (~15 packages: Solana, SolanaWallet, solananet, solnetplus, solnetall, solnetunified, solnetwallet.net.core), WPF/WinForms UI-kit typosquats (~40 packages: WPF-UI-Net, WpfAnimatedGif.Net, WpfLightToolkit.Net, LiveCharts.net, Bunifu.*), Oracle Cloud SDK impersonators (OCI.DotNetSDK.*, ~25 packages), and crypto-exchange API impersonators (Binance, Kucoin, Kraken, Bybit, Coinbase, Huobi, Ripple).

typosquatcrypto-wallet-draincredential-theftdependency-confusion
Detected by
GitHub Advisory Database · OpenSSF Package Analysis · NuGet Security
Also known as
2026-07-20 GHSA NuGet backfill · NuGet Solana wallet typosquat sweep · NuGet WPF/WinForms UI typosquat sweep · NuGet Oracle OCI SDK typosquat sweep
Ecosystems
NuGet
Packages tracked
174

What happened

On 2026-07-20 GitHub's Advisory Database published ~264 CWE-506 (Embedded Malicious Code) advisories against NuGet packages in a single-day sweep — the largest single-day NuGet malware batch on record. Every record uses the standard "any computer that has this package installed or running should be considered fully compromised — rotate all secrets from a different computer" boilerplate.

The 264-package count and the specific mix of long-established typosquat targets (Solnet, LiveCharts, WpfAnimatedGif, Nethereum, Bunifu, OCI.DotNetSDK) reads as a GHSA / OpenSSF backfill import — GitHub retroactively cataloguing pre-existing NuGet malware that had been detected elsewhere (OpenSSF Package Analysis dataset, Microsoft Defender for Cloud NuGet feed, or a similar tracker) rather than reflecting a single 2026-07-20 attacker action. Regardless of when the packages first shipped to nuget.org, the advisories became authoritative on 2026-07-20 and lockfile-lookup coverage is now available to defenders.

Cluster 1 — Solana / crypto wallet impersonator cluster (~15 packages)

Targets .NET developers integrating Solana / Ethereum / Bitcoin / Litecoin wallet functionality — typosquats and near-name matches of the legitimate Solnet (Solana .NET SDK), Nethereum (Ethereum .NET SDK), and NBitcoin/BitcoinLib (Bitcoin .NET SDKs) packages. Names include Solana, SolanaWallet, solananet, solnetplus, solnetall, solnetall.net, solnetunified, solnetwallet.net.core, Notus.Wallet.Utility.Net, LedgerWallet.Net, nethereumunified, Litecoin, bitcoincore, BitcoinLib.Net, SharpCashAddr.Core.

Cluster 2 — WPF / WinForms UI-kit typosquat cluster (~40 packages)

Impersonates legitimate WPF/WinForms UI toolkits by adding .Net, .Core, .WinForms.net, .Wpf.net, or capitalization/hyphen variants to real package names. Notable targets: WPF-UI-Net (typosquat of Wpf-UI), Bunifu.* (multiple typosquats of Bunifu.UI.WinForms), LiveCharts.net/LiveCharts.Wpf.net/LiveCharts.WinForms.net/Live.Charts.WinForm (all typosquats of LiveCharts), WpfAnimatedGif.Net (typosquat of WpfAnimatedGif), Sanka.UI* / Shade.* / MetroModern.UI2 / ReaLTaiizor-WinForm variants. Also includes WindowsAPICodePack.Net, WinForms, Xam.Plugins.Forms.Svg.Net, Rg.Plugins.Popups.Net, CefSharp.WinForm.Net.Core, OpenCvSharp4.WpfExtensions.Net, and Portable.Xaml.Net.

Cluster 3 — Oracle Cloud OCI SDK impersonator cluster (~25 packages)

Impersonates Oracle's official OCI SDK for .NET namespace OCI.DotNetSDK.* by targeting individual OCI service SDKs — cloud AI vision/speech, certificates management, dashboard service, data labelling, file storage, threat intelligence, WAF, service manager, database tools, and OSuB (Oracle Subscription) billing/usage/organization/subscription. Any lockfile hit here means the .NET dev host installed a typosquatted OCI SDK — treat Oracle Cloud credentials accessible from that host as compromised.

Cluster 4 — Crypto-exchange & popular-API impersonator cluster (~20 packages)

  • Crypto exchanges: Binance.Library / Binance.Libary (typo) / binance.csharp, Bybit.Net.Core, Kucoin.Net.Core, KrakenExchange.Net.Core, Huobi.Net.Core, Coinbase.Api, Ripple.NetCore.Api.
  • Payment: stripeapi.net, PayPalMerchant.SDK.
  • Popular APIs: Reddit.api, MailBee, Whatsapp.API, YoutubeExtractor.Net, TheOpenAI.API, Superpower-Api.
  • Zendesk cluster (6 packages): Zendesk, Zendesk-Api, Zendesk.Client, Zendesk.Drivers, Zendesk.OAuth, ZendeskApi.Client.V2 — a distinctive multi-name Zendesk-API typosquat squat.
  • Trading libraries: AlgoTrading, AlgoTrading.Net, Altcoins, Altcoins.Library.

Cluster 5 — Miscellaneous typosquat / research clusters (~40+ packages)

  • Stl.* series (11 packages) — typosquats of the ActualLab.Fusion / Stl.Fusion framework.
  • Tessa.* series (11 packages) — typosquats of the Tessa document-management platform.
  • Syntellect.Winium.* (4 packages) — typosquats of the Winium UI automation library.
  • Pathoschild.Stardew.* (2 packages) — typosquats of the popular Stardew Valley mod-build-config tool.
  • Game engine / mod impersonators: Rockstar.AssetManager.Infrastructure, Rimworld.Reference.Libary (misspelling of Library), Rimworld.References.Net, ppy.osu.Game.Lib (osu! game engine).
  • Meme / joke names: KanyeWestBrigade, KANYEWESTBRIDGADE (all-caps duplicate), KanyeWestWasRight, GetRekt420, Reothor.Lab.EvilPackage.
  • Self-labeled scanner-bait: security_hacks, seedefender, sharpdefender, KeyAuthAPI, sqzrframework480, psbuiId (typosquat of psbuild), PublishIgnor / PubIishIgnore (dep-confusion of PublishIgnore).
  • hackney.core.enums, hackney.core.jwt (typosquats of the Hackney.Core framework).
  • Test / bulk-published fillers: test6789.client, test6789.latest, test6789.v3, testt22esttest, Lfafafa2, Lfafafa3, Nughettt.TestPO, xopxopxopxopxopx, jjrawlins.cdkiampolicybuilderhelper.

Registry state

All 264 packages appear as unlisted on nuget.org (listed: false metadata). Original version tarballs are no longer resolvable via the standard NuGet feed but private NuGet feeds (Artifactory, Azure Artifacts, MyGet, on-prem nuget.exe push-based servers) that cached the tarballs during the publish window WILL keep serving the original versions after the public unlist — any lockfile hit must be treated as actionable regardless of what the public feed currently returns.

Affected packages (174)

  • NuGetAlgoTrading
  • NuGetAlgoTrading.Net
  • NuGetAltcoins
  • NuGetAltcoins.Library
  • NuGetbinance.csharp
  • NuGetBinance.Libary
  • NuGetBinance.Library
  • NuGetbitcoincore
  • NuGetBitcoinLib.Net
  • NuGetBlazor.Captcha
  • NuGetBlockcore.Networks.Bitcoin.Bc
  • NuGetbsure.binsec
  • NuGetbsure.utils
  • NuGetBunifu
  • NuGetBunifu.Form
  • NuGetBunifu.GUI
  • NuGetBunifu.UI.WinForms.Net
  • NuGetBunifu.UI2Winforms
  • NuGetBunifu.UI3Winforms
  • NuGetBybit.Net.Core
  • NuGetCaptchaCsharp
  • NuGetCefSharp.WinForm.Net.Core
  • NuGetChronos.Platform.Linux.API
  • NuGetClipboard.net
  • NuGetCodeExecTest
  • NuGetCoinbase.Api
  • NuGetGetRekt420
  • NuGetGoogleReCaptcha.V4
  • NuGethackney.core.enums
  • NuGethackney.core.jwt
  • NuGetHuobi.Net.Core
  • NuGetjjrawlins.cdkiampolicybuilderhelper
  • NuGetKANYEWESTBRIDGADE
  • NuGetKanyeWestBrigade
  • NuGetKanyeWestWasRight
  • NuGetKeyAuthAPI
  • NuGetKrakenExchange.Net.Core
  • NuGetKucoin.Net.Core
  • NuGetLedgerWallet.Net
  • NuGetLfafafa2
  • NuGetLfafafa3
  • NuGetLib.Harmony.net
  • NuGetLibEmbedder.Fody
  • NuGetLitecoin
  • NuGetLive.Charts.WinForm
  • NuGetLiveCharts.net
  • NuGetLiveCharts.WinForms.net
  • NuGetLiveCharts.Wpf.net
  • NuGetMailBee
  • NuGetmarkdown-to-html
  • NuGetMetroModern.UI2
  • NuGetnethereumunified
  • NuGetNotifyIcons
  • NuGetNotus.Wallet.Utility.Net
  • NuGetNughettt.TestPO
  • NuGetOCI.DotNetSDK.Ai.speech
  • NuGetOCI.DotNetSDK.Ai.vision
  • NuGetOCI.DotNetSDK.Apm.config
  • NuGetOCI.DotNetSDK.Appmgmtcontrol.Net
  • NuGetOCI.DotNetSDK.Certificates.Net
  • NuGetOCI.DotNetSDK.Certificatesmanagement.Net
  • NuGetOCI.DotNetSDK.Dashboard.service
  • NuGetOCI.DotNetSDK.Databasetools.Net
  • NuGetOCI.DotNetSDK.Datalabeling.service
  • NuGetOCI.DotNetSDK.File.storage
  • NuGetOCI.DotNetSDK.Net
  • NuGetOCI.DotNetSDK.Ospgateway.Net
  • NuGetOCI.DotNetSDK.Osubbillingschedule.Net
  • NuGetOCI.DotNetSDK.Osuborganizationsubscription.Net
  • NuGetOCI.DotNetSDK.Osubsubscription.Net
  • NuGetOCI.DotNetSDK.Osubusage.Net
  • NuGetOCI.DotNetSDK.Servicemanager.proxy
  • NuGetOCI.DotNetSDK.Threat.intelligence
  • NuGetOCI.DotNetSDK.Usage.Net
  • NuGetOCI.DotNetSDK.Visualbuilder.Net
  • NuGetOCI.DotNetSDK.Waf.Net
  • NuGetOpenCvSharp4.WpfExtensions.Net
  • NuGetOtpCsharp
  • NuGetPathoschild.Stardew.Mod.Build.Config
  • NuGetPathoschild.Stardew.ModBuildConfig.Net
  • NuGetPayPalMerchant.SDK
  • NuGetPDFTron.NETCore.Windows.x64.Net
  • NuGetPortable.Xaml.Net
  • NuGetppy.osu.Game.Lib
  • NuGetPrivacyGate.net
  • NuGetpsbuiId
  • NuGetPubIishIgnore
  • NuGetPublishIgnor
  • NuGetRadPdf.Net
  • NuGetReactive.GUI.Winforms
  • NuGetReaLTaiizor-WinForm
  • NuGetReddit.api
  • NuGetReothor.Lab.EvilPackage
  • NuGetResource.Embedder.Net
  • NuGetRg.Plugins.Popups.Net
  • NuGetRimworld.Reference.Libary
  • NuGetRimworld.References.Net
  • NuGetRipple.NetCore.Api
  • NuGetRockstar.AssetManager.Infrastructure
  • NuGetRSG.Base
  • NuGetSanka.UI.WinForms
  • NuGetSanka.UI2.WinForms
  • NuGetSanka.UI3.WinForms
  • NuGetsecurity_hacks
  • NuGetseedefender
  • NuGetShade.UI.WinForms
  • NuGetShade.WPF.Controls
  • NuGetSharpCashAddr.Core
  • NuGetsharpdefender
  • NuGetSimplify.Windows.Forms.Net
  • NuGetSkylark.Net
  • NuGetSoenneker.Redis.Util.Net
  • NuGetSolana
  • NuGetsolananet
  • NuGetSolanaWallet
  • NuGetsolnetall
  • NuGetsolnetall.net
  • NuGetsolnetplus
  • NuGetsolnetunified
  • NuGetsolnetwallet.net.core
  • NuGetsqzrframework480
  • NuGetStl.Blazor.Authentication.Net
  • NuGetStl.CommandLine.Net
  • NuGetStl.Fusion.Ext.Contracts.Net
  • NuGetStl.Fusion.Ext.Services.Net
  • NuGetStl.Generators.Net
  • NuGetStl.Plugins.Extensions.Net
  • NuGetStl.RestEase.Net
  • NuGetStl.Rpc.Server.Core
  • NuGetStl.Rpc.Server.Net.Fx
  • NuGetstripeapi.net
  • NuGetSuperpower-Api
  • NuGetSyntellect.Winium.Cruciatus.Net
  • NuGetSyntellect.Winium.Element
  • NuGetSyntellect.Winium.Web.Driver
  • NuGetTessa.Analyzer
  • NuGetTessa.Compilations
  • NuGetTessa.Core
  • NuGetTessa.Linux.V2
  • NuGetTessa.Net.V2
  • NuGetTessa.Postgre.Sql
  • NuGetTessa.Server.Net
  • NuGetTessa.UI2
  • NuGetTessa.Web.Client.Net
  • NuGetTessa.Web.Core
  • NuGetTessa.Windows.V2
  • NuGettest6789.client
  • NuGettest6789.latest
  • NuGettest6789.v3
  • NuGettestt22esttest
  • NuGetTheOpenAI.API
  • NuGetUI2.Guna.Winforms
  • NuGetUltimate.Wpf.Toolkit
  • NuGetvspropertypages
  • NuGetWhatsapp.API
  • NuGetWindowsAPICodePack.Net
  • NuGetWinforms
  • NuGetWPF-UI-Net
  • NuGetWpf.UI.WinForms
  • NuGetWpfAnimatedGif.Net
  • NuGetWpfLightToolkit.Net
  • NuGetWPFMediaKit.Net
  • NuGetWpfScreenHelper.Net
  • NuGetwpfuihelpercore
  • NuGetXam.Plugins.Forms.Svg.Net
  • NuGetXboxGamebar
  • NuGetxopxopxopxopxopx
  • NuGetYoutubeExtractor.Net
  • NuGetZendesk
  • NuGetZendesk-Api
  • NuGetZendesk.Client
  • NuGetZendesk.Drivers
  • NuGetZendesk.OAuth
  • NuGetZendeskApi.Client.V2

Impact

  • Any host that installed any of the packages below should be treated as fully compromised — every GHSA record uses the boilerplate CWE-506 "rotate all secrets from a different computer" language, and no patched version exists
  • Solana / crypto wallet impersonator cluster (~15 packages): Solana, SolanaWallet, solananet, solnetplus, solnetall, solnetall.net, solnetunified, solnetwallet.net.core, Notus.Wallet.Utility.Net, LedgerWallet.Net, nethereumunified, Litecoin, bitcoincore, BitcoinLib.Net, SharpCashAddr.Core. Targets .NET developers integrating Solana / Ethereum / Bitcoin / Litecoin wallet functionality — typosquats and near-name matches of the legitimate Solnet, Nethereum, NBitcoin packages
  • WPF / WinForms UI-kit typosquat cluster (~40 packages): WPF-UI-Net, WpfAnimatedGif.Net, WpfLightToolkit.Net, WpfScreenHelper.Net, WPFMediaKit.Net, wpfuihelpercore, Wpf.UI.WinForms, Ultimate.Wpf.Toolkit, LiveCharts.net, LiveCharts.Wpf.net, LiveCharts.WinForms.net, Live.Charts.WinForm, Bunifu, Bunifu.Form, Bunifu.GUI, Bunifu.UI.WinForms.Net, Bunifu.UI2Winforms, Bunifu.UI3Winforms, ReaLTaiizor-WinForm, Sanka.UI.WinForms, Sanka.UI2.WinForms, Sanka.UI3.WinForms, Shade.WPF.Controls, Shade.UI.WinForms, MetroModern.UI2, Reactive.GUI.Winforms, Simplify.Windows.Forms.Net, WindowsAPICodePack.Net, WinForms, Xam.Plugins.Forms.Svg.Net, Rg.Plugins.Popups.Net, CefSharp.WinForm.Net.Core, OpenCvSharp4.WpfExtensions.Net, Portable.Xaml.Net, Resource.Embedder.Net, UI2.Guna.Winforms, Skylark.Net — impersonates legitimate WPF/WinForms UI toolkits by adding .Net/.Core suffixes to real package names
  • Oracle Cloud OCI SDK impersonator cluster (~25 packages): OCI.DotNetSDK.Net, OCI.DotNetSDK.Ai.speech, OCI.DotNetSDK.Ai.vision, OCI.DotNetSDK.Apm.config, OCI.DotNetSDK.Appmgmtcontrol.Net, OCI.DotNetSDK.Certificates.Net, OCI.DotNetSDK.Certificatesmanagement.Net, OCI.DotNetSDK.Dashboard.service, OCI.DotNetSDK.Databasetools.Net, OCI.DotNetSDK.Datalabeling.service, OCI.DotNetSDK.File.storage, OCI.DotNetSDK.Osubbillingschedule.Net, OCI.DotNetSDK.Osubusage.Net, OCI.DotNetSDK.Osubsubscription.Net, OCI.DotNetSDK.Osuborganizationsubscription.Net, OCI.DotNetSDK.Ospgateway.Net, OCI.DotNetSDK.Servicemanager.proxy, OCI.DotNetSDK.Threat.intelligence, OCI.DotNetSDK.Usage.Net, OCI.DotNetSDK.Waf.Net, OCI.DotNetSDK.Visualbuilder.Net — impersonates the legitimate Oracle Cloud SDK OCI.DotNetSDK.* namespace by targeting individual OCI service SDKs
  • Crypto-exchange & payment API impersonator cluster (~20 packages): Binance.Library, Binance.Libary, binance.csharp, Bybit.Net.Core, Kucoin.Net.Core, KrakenExchange.Net.Core, Huobi.Net.Core, Coinbase.Api, Ripple.NetCore.Api, stripeapi.net, PayPalMerchant.SDK, Reddit.api, MailBee, Whatsapp.API, YoutubeExtractor.Net, TheOpenAI.API, Superpower-Api, AlgoTrading, AlgoTrading.Net, Altcoins, Altcoins.Library, Zendesk, Zendesk-Api, Zendesk.Client, Zendesk.Drivers, Zendesk.OAuth, ZendeskApi.Client.V2 — impersonators of major crypto-exchange (Binance, Kucoin, Kraken, Bybit, Coinbase, Huobi, Ripple) and popular API (Zendesk, Stripe, PayPal, Reddit, YouTube, OpenAI, WhatsApp, MailBee) SDKs
  • Miscellaneous typosquat / research cluster (~40+ packages): Stl.* series (11 packages: Stl.Blazor.Authentication.Net, Stl.CommandLine.Net, Stl.Fusion.Ext.Contracts.Net, Stl.Fusion.Ext.Services.Net, Stl.Generators.Net, Stl.Plugins.Extensions.Net, Stl.RestEase.Net, Stl.Rpc.Server.Core, Stl.Rpc.Server.Net.Fx), Tessa.* series (11 packages), Syntellect.Winium.* (4 packages), Pathoschild.Stardew.* (2 Stardew Valley mod-build-config typosquats), Rockstar.AssetManager.Infrastructure, Rimworld.Reference.Libary, Rimworld.References.Net, ppy.osu.Game.Lib (osu! game engine impersonator), NotifyIcons, PublishIgnor, PubIishIgnore, psbuiId (typosquat of psbuild), KanyeWestBrigade, KANYEWESTBRIDGADE, KanyeWestWasRight, GetRekt420, hackney.core.enums, hackney.core.jwt, Lfafafa2, Lfafafa3, KeyAuthAPI, security_hacks, seedefender, sharpdefender, sqzrframework480, Reothor.Lab.EvilPackage
  • The 264-package single-day count and the specific mix of long-established typosquat targets (Solnet, LiveCharts, WpfAnimatedGif, Nethereum, Bunifu, OCI.DotNetSDK) makes this look like a GHSA / OpenSSF backfill import — GitHub retroactively cataloguing pre-existing NuGet malware from another feed rather than reflecting a single 2026-07-20 attacker action. Regardless of when the packages first shipped, the advisories became authoritative on 2026-07-20 and lockfile-lookup coverage is now available
  • None of the 264 packages have surviving version tarballs on the public NuGet gallery — all appear as "listed: false" / unlisted. Private NuGet feeds (Artifactory, Azure Artifacts, MyGet, on-prem servers) that cached the tarballs during the publish window WILL keep serving them after the public unlist

What to do

  1. 1Grep every .csproj, packages.config, packages.lock.json, and paket.lock for each name in the packages map below. Any match is a supply-chain incident: rotate every credential the build host and downstream .NET runtime could reach, and re-image the affected workstation
  2. 2*If you had any Solana, SolanaWallet, `solnet, nethereumunified, Notus.Wallet.Utility.Net, LedgerWallet.Net, bitcoincore, BitcoinLib.Net, Litecoin` package**: treat all crypto wallets, private keys, mnemonic seeds, and Ledger device tokens accessible from the affected .NET dev host or CI runner as compromised — this cluster is specifically targeted at .NET developers integrating cryptocurrency wallet functionality. Move funds to a new wallet from a clean device
  3. 3*If you had any WPF-UI-Net, `Bunifu., LiveCharts., Wpf, WinForms, MetroModern.UI2, Sanka.UI, Shade., ReaLTaiizor-WinForm, Ultimate.Wpf.Toolkit, or similar UI toolkit package**: these are typosquats of legitimate WPF/WinForms UI libraries (e.g. WPF-UI, Bunifu.UI.WinForms, LiveCharts, WpfAnimatedGif). Check the real package name letter-by-letter — legitimate WPF-UI is at Wpf-UI (single hyphen, no .Net suffix), Bunifu.UI.WinForms is the trademarked publisher name (typosquat variants add Net/Core), LiveCharts is a specific publisher's package (typosquats add .net/.Wpf.net/.WinForms.net`)
  4. 4*If you had any `OCI.DotNetSDK.` package**: verify the exact publisher and namespace against Oracle's official OCI SDK for .NET — the legitimate Oracle-published packages live under a specific publisher account, and the 25-package typosquat cluster above adds extra service suffixes or capitalization variants that Oracle does not ship
  5. 5*If you had any `Binance., Kucoin., Kraken, Bybit., Coinbase., Huobi., Ripple., stripeapi.net, PayPalMerchant.SDK, Reddit.api, Whatsapp.API, YoutubeExtractor.Net, TheOpenAI.API, Zendesk` package*: these are typosquats of legitimate exchange/payment/API SDKs. The legitimate packages use different publisher accounts; verify against each API vendor's official NuGet publisher page
  6. 6Verify none of the 264 listed packages still resolves via your private NuGet feed — internal Artifactory / Azure Artifacts / MyGet instances routinely cache tarballs and will keep serving the original versions after the public unlist
  7. 7For .NET projects with the <RestorePackagesConfig>true</RestorePackagesConfig> setting or that use packages.lock.json, rebuild the lock file from a clean nuget.config that pins the official api.nuget.org feed with signature verification enabled — some of the typosquats above ship without the standard Microsoft/organization signing certificates that the legitimate SDKs carry

References

nuget-2026-07-20-ghsa-backfill-sweep