Malicious code in Zendesk-Api (NuGet)
Malicious code was discovered in multiple versions of the Zendesk-Api NuGet package. The incident was identified and documented by the OpenSSF malicious-packages project (MAL-2024-4708).
- Disclosed
- Last updated
- Blast radius
- Multiple versions of Zendesk-Api NuGet package; impact scope depends on adoption and version pinning practices among .NET consumers.
- Ecosystems
- Attack vectors
- Affected entities
- Zendesk-ApiNuGet package with malicious code in multiple versions
Multiple versions of the Zendesk-Api NuGet package were found to contain malicious code. The vulnerability was identified and credited to the OpenSSF's malicious-packages initiative, which maintains a public catalog of known malicious software packages.\n\nThe affected package is Zendesk-Api distributed via NuGet, the official package manager for .NET. The incident was assigned identifier MAL-2024-4708 in the OpenSSF malicious-packages repository.\n\nThe advisory was published on 2026-07-20 via GitHub's security advisory system (GHSA-vc2w-9pj4-6qch). Consumers of this package should immediately audit their dependencies and remove or update affected versions.
Indicators of compromise
- Packages
- Zendesk-Api
Remediation
- Identify all projects and applications using Zendesk-Api NuGet package
- Remove or update to a patched version of Zendesk-Api
- Audit code for any suspicious behavior introduced by malicious versions
- Review access logs and security events for systems that may have executed malicious code
- Consider using alternative Zendesk API client libraries if available
- Implement package verification and integrity checks in your build pipeline
Sources
- GitHub Advisory GHSA-vc2w-9pj4-6qch · GitHub Advisory Database
Cite this entry
"Malicious code in Zendesk-Api (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2026; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-zendesk-api-nuget-ol6zlk
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in intercom-php (Packagist)
The intercom-php package on Packagist was compromised with malicious code as part of the Mini Shai-Hulud campaign by the TeamPCP threat actor. The malicious payload steals credentials and can propagate to NPM packages using discovered credentials.
Mini Shai HuludTeamPCPNuGetCompromised packageMalicious maintainer - resolvedcritical
Malicious code in Simplify.Windows.Forms.Net (NuGet)
Malicious code was discovered in the Simplify.Windows.Forms.Net NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4642.
NuGetCompromised package - resolvedcritical
Malicious code in Tessa.Compilations (NuGet)
Malicious code was discovered in the Tessa.Compilations NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
NuGetCompromised package - resolvedcritical
Malicious code in Syntellect.Winium.Web.Driver (NuGet)
Malicious code was discovered in the Syntellect.Winium.Web.Driver NuGet package. The package was flagged by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4668.
NuGetCompromised package