Malicious code in ZendeskApi.Client.V2 (NuGet)
Malicious code was discovered in multiple versions of the ZendeskApi.Client.V2 NuGet package. The incident was identified and documented by the OpenSSF malicious packages project.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on adoption of affected versions
- Ecosystems
- Attack vectors
- Affected entities
- ZendeskApi.Client.V2Multiple versions affected
Multiple versions of the ZendeskApi.Client.V2 NuGet package were found to contain malicious code. The vulnerability was identified and tracked by the OpenSSF's malicious packages initiative, which maintains a public database of known malicious software supply chain incidents.\n\nThe affected package is a .NET client library for the Zendesk API. The presence of malicious code in multiple versions suggests either a compromised package publication process or a malicious maintainer action.\n\nUsers of ZendeskApi.Client.V2 should immediately audit their dependencies and upgrade to a patched version if available, or remove the package entirely if no safe version exists.
Indicators of compromise
- Packages
- ZendeskApi.Client.V2
Remediation
- Identify all projects using ZendeskApi.Client.V2 and audit for the affected versions
- Remove or upgrade ZendeskApi.Client.V2 to a non-malicious version if available
- Review package source integrity and consider pinning to verified versions
- Monitor for any suspicious activity or data exfiltration from systems that may have used the malicious package
- Report the incident to NuGet package maintainers and security teams
Sources
- GitHub Advisory GHSA-pf6h-947h-83qm · GitHub Advisory Database
Cite this entry
"Malicious code in ZendeskApi.Client.V2 (NuGet)." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 20, 2024; last updated July 20, 2026. https://supplychainattack.org/incident/malicious-code-in-zendeskapi-client-v2-nuget-1e27lv
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- resolvedcritical
Malicious code in Reothor.Lab.EvilPackage (NuGet)
Malicious code was discovered in multiple versions of the Reothor.Lab.EvilPackage NuGet package. The package was identified by the OpenSSF malicious-packages project and assigned identifier MAL-2024-4626.
NuGetCompromised package - resolvedcritical
Malicious code in seedefender (NuGet)
Malicious code was discovered in the seedefender NuGet package. The incident was identified and reported via the OpenSSF malicious packages database.
NuGetCompromised package - resolvedcritical
Malicious code in Ripple.NetCore.Api (NuGet)
Malicious code was discovered in the Ripple.NetCore.Api NuGet package. The OpenSSF malicious packages project identified and documented the compromise under identifier MAL-2024-4631.
NuGetCompromised package - resolvedcritical
Malicious code in Resource.Embedder.Net (NuGet)
Malicious code was discovered in the Resource.Embedder.Net NuGet package. The package was identified by the OpenSSF malicious packages project as containing malicious code.
NuGetCompromised package