Malicious code in Ultimate.Wpf.Toolkit (NuGet)
Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.
- Disclosed
- Last updated
- Blast radius
- Multiple versions of Ultimate.Wpf.Toolkit on NuGet; exact scope unclear from source
- Ecosystems
- Attack vectors
- Affected entities
- Ultimate.Wpf.ToolkitNuGet package with malicious code in multiple versions
The Ultimate.Wpf.Toolkit package on NuGet was found to contain malicious code across multiple versions. This incident was identified and tracked by the OpenSSF's malicious packages project (reference MAL-2024-4691).\n\nThe package is a .NET/NuGet ecosystem component, and the presence of malicious code in multiple published versions indicates a compromised package scenario. The exact nature of the malicious payload and the full list of affected versions are referenced in the OpenSSF malicious packages repository.\n\nDevelopers who installed affected versions of Ultimate.Wpf.Toolkit should remove the package and audit their systems for any suspicious activity or data exfiltration.
Indicators of compromise
- Packages
- Ultimate.Wpf.Toolkit
Remediation
- Remove Ultimate.Wpf.Toolkit from affected projects immediately
- Audit project dependencies and build artifacts for signs of compromise
- Review application logs and system activity during the period when the malicious package was installed
- Consider using alternative WPF toolkit packages from trusted sources
- Monitor NuGet security advisories for updates on this incident
Sources
- GitHub Advisory GHSA-m9mf-f7gx-x34w · GitHub Advisory Database
Cite this entry
"Malicious code in Ultimate.Wpf.Toolkit (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-ultimate-wpf-toolkit-nuget-1tvkzs
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in YoutubeExtractor.Net (NuGet)
Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Zendesk.OAuth (NuGet)
Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Winforms (NuGet)
Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.
NuGetCompromised package - resolvedcritical
Malicious code in WPFMediaKit.Net (NuGet)
Malicious code was discovered in the WPFMediaKit.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package