Malicious code in Simplify.Windows.Forms.Net (NuGet)
Malicious code was discovered in the Simplify.Windows.Forms.Net NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4642.
- Disclosed
- Last updated
- Blast radius
- NuGet package ecosystem; all consumers of affected Simplify.Windows.Forms.Net versions
- Ecosystems
- Attack vectors
- Affected entities
- Simplify.Windows.Forms.NetMalicious code detected in NuGet package
The Simplify.Windows.Forms.Net package on NuGet was found to contain malicious code. This discovery was credited to the OpenSSF's malicious packages tracking initiative, which maintains a public repository of known malicious software supply chain incidents.\n\nThe incident was documented in the OpenSSF malicious packages database with identifier MAL-2024-4642. The affected package is hosted on the NuGet package manager, which serves the .NET ecosystem.\n\nAny system that installed affected versions of Simplify.Windows.Forms.Net should be considered potentially compromised and remediated accordingly.
Indicators of compromise
- Packages
- Simplify.Windows.Forms.Net
Remediation
- Remove all versions of Simplify.Windows.Forms.Net from affected systems
- Audit systems that installed this package for signs of compromise
- Review package dependencies and replace with legitimate alternatives
- Update to a clean, verified version if the package is still needed
- Monitor NuGet security advisories for related incidents
Sources
- GitHub Advisory GHSA-vjx6-7vh7-q6jm · GitHub Advisory Database
Cite this entry
"Malicious code in Simplify.Windows.Forms.Net (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-simplify-windows-forms-net-nuget-3klgyb
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in Ultimate.Wpf.Toolkit (NuGet)
Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in YoutubeExtractor.Net (NuGet)
Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.OAuth (NuGet)
Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Winforms (NuGet)
Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.
NuGetCompromised package