Threat reportSupply ChainTL-2026-1876

Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)

mediumACTIVE

Microsoft shortens NuGet.org API key lifetimes to 30 days (TL-2026-1876), also tracked as NuGet API key lifetime reduction, is a medium-severity supply-chain compromise, first published 2026-08-04. It has no confirmed attribution, affects Microsoft NuGet.org API keys, references 2 CVEs (CVE-2026-45321, CVE-2026-48027), maps to 17 MITRE ATT&CK techniques (T1005, T1027.005, T1055), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
2Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1876

Threat ID
TL-2026-1876
Also known as
NuGet API key lifetime reduction, NuGet Trusted Publishing migration
Severity
MEDIUM
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
software, technology, open-source, cloud, finance
Target regions
Global
Detection rules
9
Indicators of compromise
23

Malware and tooling in Microsoft shortens NuGet.org API key lifetimes to 30 days

Malware and tooling: Necrobit, cat.py, we4ftg.exe, .NET Reactor

How Microsoft shortens NuGet.org API key lifetimes to 30 days works

Microsoft is strengthening NuGet.org supply-chain security by reducing the maximum validity of newly created NuGet.org API keys from 365 days to 30 days, effective August 17, 2026. All API keys created before that date will expire on November 1, 2026. Microsoft strongly recommends migrating to NuGet Trusted Publishing (launched September 2025), which uses OpenID Connect (OIDC) to authenticate CI/CD publishing without any long-lived shared secret. The change follows a series of high-profile package-manager credential theft incidents, including the Nx Console npm extension compromise (CVE-2026-48027) where a stolen credential published a malicious release activated 6,000 times in 36 minutes, and a concurrent NuGet infostealer campaign typosquatting Chinese .NET libraries (~65,000 downloads).

On August 4, 2026, Microsoft announced a significant hardening of NuGet.org package publishing security: the maximum validity of newly created NuGet.org API keys will be reduced from 365 days to 30 days, effective August 17, 2026. All API keys created before that date will be forcibly expired on November 1, 2026. This change eliminates the 365-day key duration option and is intended to reduce the damage window of stolen or leaked publishing credentials.

NuGet.org API keys function as passwords for publishing packages. Developers commonly store them as secrets in CI/CD platforms, repository settings, build servers, and deployment configurations. A stolen long-lived key enables an attacker to publish trojanized package updates under a trusted project name for months before the credential expires or is noticed. The problem is cross-ecosystem: npm experienced the same pattern with the ua-parser-js, coa, and rc package takeovers (October–November 2021), where stolen maintainer credentials via credential stuffing were used to publish DanaBot password-stealing trojans and XMRig cryptominers. PyPI, RubyGems, and crates.io have all faced similar credential-theft supply-chain incidents.

Two specific incidents drove the urgency of the NuGet policy change. First, the Nx Console supply-chain compromise (CVE-2026-48027, GHSA-c9j4-9m59-847w) on May 18, 2026: an attacker published a malicious Nx Console VSCode extension version (v18.95.0) after exfiltrating a contributor’s GitHub CLI OAuth token. The theft originated from the upstream TanStack npm compromise (CVE-2026-45321, GHSA-g7cv-rxg3-hmpx) on May 11, 2026, where 84 malicious @tanstack/* packages were published with valid npm provenance. When a Nx contributor ran pnpm install in an external repo, a malicious prepare script executed a 2.3 MB obfuscated credential harvester that exfiltrated the contributor’s gh CLI token from ~/.config/gh/hosts.yml within 74 seconds. The attacker then spent 5+ days with the stolen token deleting CodeQL workflow runs and planting orphan commits before publishing the malicious extension, which was activated approximately 6,000 times in 36 minutes across VS Code and Cursor installations. The root cause chain included four compounding failures: an upstream dependency compromise with valid provenance, a silent minimum-release-age bypass (pnpm 10.14 silently ignored the 7-day release-age policy in .npmrc because the feature only shipped in pnpm 10.16+), gh CLI credentials readable by any local process, and a single-actor publishing pipeline lacking approval gating.

Second, concurrent research by Socket’s Threat Research Team identified five malicious NuGet packages published under the account bmrxntfj that typosquat Chinese .NET UI libraries (AntdUI-derived). The packages — IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32 — carry a .NET Reactor-protected infostealer targeting credentials from 12 Chromium-based browsers, 8 desktop cryptocurrency wallets, 5 browser wallet extensions (MetaMask, TronLink, Phantom, Trust Wallet, Coinbase Wallet), SSH private keys, and cloud service credentials. The payload fires via the CLR module initializer, patches clrjit.dll!getJit to hijack the JIT compiler, and executes a 786 KB MSIL assembly (we4ftg.exe) recovered from live memory dumps. The operator uses version rotation evasion — 219 of 224 total versions carry listed: false, keeping only one version visible at a time while invalidating file-hash-based IOCs. The C2 domain dns-providersa2.com (registered 2026-03-12 via Njalla privacy registrar, hosted at 62.84.102.85 on VDSINA/ASN 216071 in Amsterdam) serves /check (beacon) and /upload (exfiltration) endpoints. Data is staged at C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltration. The packages have accumulated approximately 64,784 total downloads since September 2025 and remain live on NuGet.org.

Microsoft’s recommended alternative to API keys is NuGet Trusted Publishing, launched September 24, 2025. This uses OpenID Connect (OIDC) to let CI/CD workflows authenticate to NuGet.org without storing any long-lived shared secret. The workflow requests a signed, short-lived identity token from the CI/CD platform (GitHub Actions or GitLab); NuGet.org validates the token cryptographically against a policy configured by the package owner (repository, workflow, optional environment details) and issues a single-use temporary API key valid for approximately one hour. Key benefits include no long-lived secrets in repositories or CI/CD secret stores, automatic credential expiration, workload identity validation, and no manual secret rotation. For private GitHub repositories, new policies undergo a 7-day pending activation period to prevent resurrection attacks (where a deleted repository is recreated under the same name by a different owner). Community concerns raised in comments to the announcement include the lack of org-level cross-account support for Trusted Publishing (GitHub issue #10581), the absence of Azure DevOps OIDC support, and the practical pain of 30-day key rotation for teams without CI/CD OIDC support.

The change is part of a broader industry shift toward secure, keyless package publishing aligned with the OpenSSF Securing Software Repositories Working Group’s Trusted Publishers for All Package Repositories initiative. GitHub has proposed a parallel plan for npm that includes deprecating classic tokens, requiring FIDO-based 2FA, limiting granular tokens to 7-day expiration, and expanding trusted publishing to CircleCI (April 2026) and others. NuGet.org’s Trusted Publishing currently supports GitHub Actions and GitLab, with additional CI/CD environments under development. Microsoft has indicated that API key durations may be reduced further in the future as Trusted Publishing adoption grows.

MITRE ATT&CK techniques used in TL-2026-1876

Collection

T1005 Data from Local System

Defense Evasion

T1027.005 Indicator Removal from Tools; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information

Execution

T1059.007 JavaScript

Command and Control

T1071.001 Web Protocols; T1071.004 DNS

Initial Access

T1078 Valid Accounts; T1195.001 Compromise Software Dependencies and Development Tools; T1195.002 Compromise Software Supply Chain

Persistence

T1543.001 Launch Agent

Privilege Escalation

T1548.003 Sudo and Sudo Caching

Credential Access

T1552.001 Credentials In Files; T1552.004 Private Keys; T1555.003 Credentials from Web Browsers; T1555.005 Password Managers

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Microsoft shortens NuGet.org API key lifetimes to 30 days

  • Microsoft — NuGet.org API keys
    Vulnerable versions: 365-day lifetime keys (pre-2026-08-17)
    Fixed in: 30-day maximum lifetime keys (post-2026-08-17); Trusted Publishing OIDC (launched 2025-09-24)
  • Microsoft — NuGet.org package publishing
    Vulnerable versions: Long-lived reusable API keys with 365-day maximum
    Fixed in: OIDC-based Trusted Publishing with ~1-hour temporary keys; 30-day API key maximum
  • GitHub — GitHub Actions NuGet publishers
    Vulnerable versions: Long-lived API keys stored in CI/CD secrets
    Fixed in: NuGet/login@v1 OIDC trusted publishing flow
  • GitLab — GitLab CI/CD NuGet publishers
    Vulnerable versions: Long-lived API keys in CI/CD variables
    Fixed in: OIDC trusted publishing via id_tokens with NuGet.org token exchange

Remediation for Microsoft shortens NuGet.org API key lifetimes to 30 days

Patches

  • Upgrade pnpm to 10.16+ so minimum-release-age is enforced (Nx Console lesson learned)
  • Update NuGet client and dotnet SDK to latest versions supporting Trusted Publishing
  • Pin GitHub Action SHAs to specific commits rather than version tags

Immediate actions

  • Migrate NuGet publishing workflows to Trusted Publishing (OIDC) before 2026-11-01
  • Audit, rotate, and replace all NuGet.org API keys created before 2026-08-17
  • Revoke any exposed or leaked NuGet API keys immediately
  • Remove API keys from source code, CI/CD logs, and secret stores
  • Ensure NuGet.org expiration-notification emails reach an actively monitored account

Workarounds

  • Rotate API keys on a ≤30-day cadence if Trusted Publishing is unavailable
  • Use the narrowest possible package scope and permissions for remaining API keys
  • Store API keys only in managed CI/CD secret stores, never in repository files or environment variables

Longer-term hardening

  • Adopt short-lived OIDC-based publishing across all package registries (NuGet, npm, PyPI, etc.)
  • Enforce FIDO-based 2FA/MFA for all package publishing accounts
  • Monitor package-publishing audit logs and workflow-run deletions for anomalies
  • Implement staged publishing with approval gating for critical packages
  • Expand Trusted Publishing to all CI/CD platforms used by the organization

CVEs associated with Microsoft shortens NuGet.org API key lifetimes to 30 days

CVE-2026-45321, CVE-2026-48027

Weaknesses (CWE) in Microsoft shortens NuGet.org API key lifetimes to 30 days

CWE-287, CWE-522, CWE-312

Timeline of Microsoft shortens NuGet.org API key lifetimes to 30 days

  • ua-parser-js npm account hijacked via credential stuffing; three malicious versions published with DanaBot payload and XMRig cryptominer (millions of downstream consumers)
  • coa and rc npm packages hijacked on the same day using same stolen-credential attack pattern and DanaBot payload infrastructure; single operator working from credential breach databases
  • NuGet Trusted Publishing launched with OIDC support for GitHub Actions; enables keyless publishing via short-lived identity tokens and temporary API keys (~1 hour validity)
  • Malicious C2 domain dns-providersa2.com registered via Njalla privacy registrar (NuGet infostealer campaign); hosted at 62.84.102.85 (VDSINA, ASN 216071, Amsterdam)
  • Nx contributor's GitHub CLI OAuth token exfiltrated via malicious prepare script in @tanstack/zod-adapter@1.166.15 during pnpm install; token stolen within 74 seconds from ~/.config/gh/hosts.yml
  • TanStack npm supply-chain compromise: 84 malicious @tanstack/* packages published via OIDC trusted-publisher manipulation with valid npm provenance (CVE-2026-45321, GHSA-g7cv-rxg3-hmpx)
  • Malicious Nx Console v18.95.0 published to VS Marketplace and Open VSX using stolen VSCE_PAT; activated ~6,000 times in 36 minutes; payload harvested credentials, wrote backdoors, targeted Vault, AWS, GitHub, 1Password, and Claude Code (CVE-2026-48027, GHSA-c9j4-9m59-847w)
  • Microsoft announces NuGet.org API key lifetime reduction from 365 days to 30 days, effective August 17, 2026; all pre-existing keys expire November 1, 2026
  • New NuGet.org API keys capped at 30-day maximum validity; 365-day key duration option removed
  • All NuGet.org API keys created before August 17, 2026 forcibly expire; maintainers must have migrated to Trusted Publishing or rotated keys by this date

Sources cited for Microsoft shortens NuGet.org API key lifetimes to 30 days

Detection coverage for TL-2026-1876

As of 2026-08-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1876 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats