Maarten Balliauw 5/5/2021

Building a supply chain attack with .NET, NuGet, DNS, source generators, and more!

Read Original

This article investigates the mechanisms behind software supply chain attacks in the .NET ecosystem. It demonstrates a proof-of-concept using a seemingly innocent NuGet package, source generators, and DNS to exfiltrate data, highlighting vulnerabilities and what developers should be aware of to secure their development pipelines.

Building a supply chain attack with .NET, NuGet, DNS, source generators, and more!

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

1
The Beautiful Web
Jens Oliver Meiert 2 votes
2
Container queries are rad AF!
Chris Ferdinandi 2 votes
3
Wagon’s algorithm in Python
John D. Cook 1 votes
5
Top picks — 2026 January
Paweł Grzybek 1 votes
6
In Praise of –dry-run
Henrik Warne 1 votes
8
Vibe coding your first iOS app
William Denniss 1 votes