Malicious code in Pathoschild.Stardew.Mod.Build.Config (NuGet)
Malicious code was discovered in the Pathoschild.Stardew.Mod.Build.Config NuGet package. The package was identified by the OpenSSF malicious packages project and published as a critical security advisory.
- Disclosed
- Last updated
- Blast radius
- Developers using Pathoschild.Stardew.Mod.Build.Config in their build pipelines
- Ecosystems
- Attack vectors
- Affected entities
- Pathoschild.Stardew.Mod.Build.ConfigNuGet package containing malicious code
The Pathoschild.Stardew.Mod.Build.Config NuGet package was found to contain malicious code. This package is used as a build configuration tool for Stardew Valley mods and would be executed during the build process of dependent projects.\n\nThe malicious package was identified and documented by the OpenSSF (Open Source Security Foundation) as part of their malicious packages tracking effort. The advisory was published on July 20, 2026, and assigned GitHub Security Advisory identifier GHSA-mqj7-4g3w-774j.\n\nDevelopers who included this package in their build pipelines would have been at risk of code execution during the build process. The package has since been removed or remediated.
Indicators of compromise
- Packages
- Pathoschild.Stardew.Mod.Build.Config
Remediation
- Remove the affected version(s) of Pathoschild.Stardew.Mod.Build.Config from your project dependencies
- Audit your build logs and environment for any suspicious activity during builds that used this package
- Update to a clean, verified version of the package if available
- Review any build artifacts or outputs generated while using the malicious package
- Consider rotating any credentials or secrets that may have been exposed during builds
Sources
- GitHub Advisory GHSA-mqj7-4g3w-774j · GitHub Advisory Database
Cite this entry
"Malicious code in Pathoschild.Stardew.Mod.Build.Config (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed January 1, 2024; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-pathoschild-stardew-mod-build-config-nuget-vfktbr
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in Reothor.Lab.EvilPackage (NuGet)
Malicious code was discovered in multiple versions of the Reothor.Lab.EvilPackage NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4626.
NuGetCompromised package - resolvedcritical
Malicious code in seedefender (NuGet)
Malicious code was discovered in the seedefender NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Ripple.NetCore.Api (NuGet)
Malicious code was discovered in the Ripple.NetCore.Api NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4631.
NuGetCompromised package - resolvedcritical
Malicious code in Resource.Embedder.Net (NuGet)
Malicious code was discovered in the Resource.Embedder.Net NuGet package. The package was identified by the OpenSSF malicious packages project as containing malicious code.
NuGetCompromised package