Skip to content
supplychainattack.orgSupply chain attack incident catalog
resolvedcritical

Malicious code in WpfAnimatedGif.Net (NuGet)

Malicious code was discovered in multiple versions of the WpfAnimatedGif.Net NuGet package. The compromise was identified and documented by the OpenSSF malicious packages project.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
All users of affected WpfAnimatedGif.Net NuGet package versions
Ecosystems
Attack vectors
Affected entities
  • WpfAnimatedGif.NetNuGet package with malicious code

The WpfAnimatedGif.Net NuGet package was found to contain malicious code across multiple versions. This incident was identified and cataloged by the OpenSSF's malicious packages initiative, which tracks confirmed supply chain compromises.\n\nThe malicious package was published on NuGet and could have affected any developer who installed the compromised versions. The incident was assigned identifier MAL-2024-4699 in the OpenSSF malicious packages database.\n\nUsers of this package should immediately remove or update to a known-clean version, and review any systems that may have executed code from the compromised versions.

Indicators of compromise

Packages
  • WpfAnimatedGif.Net

Remediation

  • Remove or uninstall all versions of WpfAnimatedGif.Net from affected systems
  • Review NuGet package history and identify which versions were installed
  • Check for any suspicious activity or unauthorized access on systems that used the compromised package
  • Update to a patched or alternative package version if available
  • Audit dependencies and build artifacts that may have incorporated the malicious package

Sources

  1. GitHub Advisory GHSA-87cg-q25x-6wmr · GitHub Advisory Database

Cite this entry

"Malicious code in WpfAnimatedGif.Net (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-wpfanimatedgif-net-nuget-165azf

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. resolvedcritical

    Malicious code in Ultimate.Wpf.Toolkit (NuGet)

    Multiple versions of the Ultimate.Wpf.Toolkit NuGet package contained malicious code. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  2. resolvedcritical

    Malicious code in YoutubeExtractor.Net (NuGet)

    Malicious code was discovered in the YoutubeExtractor.Net NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  3. resolvedcritical

    Malicious code in Zendesk.OAuth (NuGet)

    Malicious code was discovered in multiple versions of the Zendesk.OAuth NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.

    NuGetCompromised package
  4. resolvedcritical

    Malicious code in Winforms (NuGet)

    Malicious code was discovered in multiple versions of the Winforms package on NuGet. The incident was documented by the OpenSSF malicious packages project and published as GitHub advisory GHSA-wq82-5xjm-57wq.

    NuGetCompromised package