Malicious code in UI2.Guna.Winforms (NuGet)
Malicious code was discovered in multiple versions of the UI2.Guna.Winforms NuGet package. The OpenSSF identified and documented the malicious package as part of their malicious packages database.
- Disclosed
- Last updated
- Blast radius
- Multiple versions of UI2.Guna.Winforms package on NuGet
- Ecosystems
- Attack vectors
- Affected entities
- UI2.Guna.WinformsMultiple versions affected
The UI2.Guna.Winforms package on NuGet was found to contain malicious code across multiple versions. This incident was identified and credited to the OpenSSF (Open Source Security Foundation), which maintains a database of known malicious packages in open source ecosystems.\n\nThe malicious package was cataloged in the OpenSSF's malicious packages repository with identifier MAL-2024-4690. Multiple versions of the UI2.Guna.Winforms package were affected by this compromise.\n\nAs a NuGet ecosystem package, this malicious code posed a risk to .NET developers who installed the affected versions as a dependency in their projects.
Indicators of compromise
- Packages
- UI2.Guna.Winforms
Remediation
- Remove UI2.Guna.Winforms from affected projects or update to a known-clean version
- Audit project dependencies for any other instances of UI2.Guna.Winforms
- Review the OpenSSF malicious packages database for additional context and affected version numbers
- Consider using dependency scanning tools to detect malicious packages in your supply chain
- Report any systems that may have installed the malicious package to your security team
Sources
- GitHub Advisory GHSA-xqwx-3q28-gjrr · GitHub Advisory Database
Cite this entry
"Malicious code in UI2.Guna.Winforms (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-ui2-guna-winforms-nuget-dwlqv4
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in Ultimate.Wpf.Toolkit (NuGet)
Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in YoutubeExtractor.Net (NuGet)
Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.OAuth (NuGet)
Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Winforms (NuGet)
Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.
NuGetCompromised package