Armando identified a malicious NuGet package designed to surveil developers working in industrial control and SCADA environments. Published on January 24, 2024 by the "yushun.zhao" account, SqzrFramework480 v24.1.24 is the first version of this package to appear on the NuGet registry. It carries Xenocode-obfuscated .NET DLLs whose payload activates when a developer loads the library into their application -- no install hook required, no build-time trigger, no suspicious command runs at package time. The surveillance begins silently at runtime. The package was subsequently removed from the NuGet registry.
Key Findings
- Malicious version: v24.1.24, published 2024-01-24; this is the first (earliest) published version; version number encodes the publish date (year.month.day); all published versions are malicious
- Entry point: No lifecycle hook -- payload fires at runtime when the developer's application loads the DLLs
- Targets: Windows -- ICS/SCADA and industrial automation developers; payload capabilities consistent with targeted industrial espionage
- Capabilities: Screenshots, microphone recording (WAV), keystroke logging, FTP exfiltration (explicit FTP protocol and external FTP utility), process injection, event log clearing, privilege manipulation, TCP socket communication
- Obfuscation: Xenocode .NET obfuscator (commercial grade); DLL impersonates file version information of another file
- Detection: Text.PUA.SupplyChain, Archive-ZIP.PUA.SupplyChain
Package Background
SqzrFramework480 v24.1.24 is the initial version of a package whose name and version numbering carry no obvious meaning. The version string "24.1.24" follows a year.month.day convention matching the exact publish date -- suggesting the actor used the build date as the version. Two follow-on versions (v1.0.0, v1.0.1) were published together on March 22, 2024, approximately two months after this initial release.
The package description is in Chinese ("follow nature" -- a Taoist idiom implying non-interference) and the publisher account "yushun.zhao" references a Gitee profile -- a Chinese software hosting platform. No source code repository is declared. Publisher account has one NuGet package, all of it malicious.
Attack Analysis
SqzrFramework480 takes a different approach from typical NuGet supply chain packages: there is no install hook, no PowerShell script in tools/, and no MSBuild .targets file. The malicious code lives entirely inside Xenocode-obfuscated .NET DLLs. The payload does not fire until a developer's application loads the library at runtime.