Malicious code in Reddit.api (NuGet)
Malicious code was discovered in multiple versions of the Reddit.api NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
- Disclosed
- Last updated
- Blast radius
- Developers and applications using affected versions of Reddit.api NuGet package
- Ecosystems
- Attack vectors
- Affected entities
- Reddit.apiNuGet package with malicious code
A supply chain attack targeting the Reddit.api NuGet package was identified, with malicious code present in multiple package versions. The compromise was documented by the OpenSSF's malicious packages initiative, which tracks known malicious software packages across package ecosystems.\n\nThe affected package is Reddit.api on NuGet, a .NET package used for Reddit API integration. Multiple versions of the package contained malicious code, indicating a sustained compromise of the package or its distribution.\n\nThe incident was tracked under OpenSSF identifier MAL-2024-4625 and published to GitHub's advisory database on July 20, 2026.
Indicators of compromise
- Packages
- Reddit.api
Remediation
- Remove or uninstall affected versions of Reddit.api from all projects and systems
- Audit code and systems that may have used the compromised package for signs of compromise
- Update to a patched or alternative version of the Reddit.api package if available
- Review NuGet package dependencies and implement package verification practices
- Monitor systems for indicators of compromise related to malicious code execution
Sources
- GitHub Advisory GHSA-4hjj-2wv4-p72c · GitHub Advisory Database
Cite this entry
"Malicious code in Reddit.api (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-reddit-api-nuget-bhrfao
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in Ultimate.Wpf.Toolkit (NuGet)
Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in YoutubeExtractor.Net (NuGet)
Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.OAuth (NuGet)
Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Winforms (NuGet)
Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.
NuGetCompromised package