Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Sicoob.Sdk masquerades as a C# SDK for Brazil's Sicoob cooperative and silently exfiltrates client IDs and PFX certificates.
- Sicoob.Sdk versions 2.0.0 through 2.0.4 were published on NuGet before the theft was discovered, according to security firm Socket.
- npm packages are reported to be targeting cloud secrets, expanding the credential‑theft threat beyond .NET ecosystems.
Why it matters: Sicoob’s customers lose the confidentiality of their banking IDs and certificates, while attackers gain the data needed to impersonate accounts and commit fraud, jeopardizing the cooperative’s trust and financial security.




