Story perspectives
Malicious NuGet Packages Target Siemens Controllers, Warn Experts
11/8/2025
40 7
1 of 1
Story summary
- Nine malicious NuGet packages identified by Socket were removed and were designed to activate destructive code between 2027 and 2028.
- The packages, including Sharp7Extend, targeted Siemens S7 programmable logic controllers used in manufacturing and were downloaded nearly 10,000 times.
- Sharp7Extend activates immediately upon installation and carries a 20 percent chance of causing application crashes.
- Experts warn organizations must audit dependencies, as systems with these packages may already be compromised.
