# Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)

> Microsoft is strengthening NuGet.org supply-chain security by reducing the maximum validity of newly created NuGet.org API keys from 365 days to 30 days, effective August 17, 2026. All API keys created before that date will expire on November 1, 2026. Microsoft strongly recommends migrating to NuGet Trusted Publishing (launched September 2025), which uses OpenID Connect (OIDC) to authenticate CI/CD publishing without any long-lived shared secret. The change follows a series of high-profile package-manager credential theft incidents, including the Nx Console npm extension compromise (CVE-2026-48027) where a stolen credential published a malicious release activated 6,000 times in 36 minutes, and a concurrent NuGet infostealer campaign typosquatting Chinese .NET libraries (~65,000 downloads).

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1876
- **ID:** TL-2026-1876
- **Severity:** MEDIUM
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 23 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45321, CVE-2026-48027

## Description

On August 4, 2026, Microsoft announced a significant hardening of NuGet.org package publishing security: the maximum validity of newly created NuGet.org API keys will be reduced from 365 days to 30 days, effective August 17, 2026. All API keys created before that date will be forcibly expired on November 1, 2026. This change eliminates the 365-day key duration option and is intended to reduce the damage window of stolen or leaked publishing credentials.

NuGet.org API keys function as passwords for publishing packages. Developers commonly store them as secrets in CI/CD platforms, repository settings, build servers, and deployment configurations. A stolen long-lived key enables an attacker to publish trojanized package updates under a trusted project name for months before the credential expires or is noticed. The problem is cross-ecosystem: npm experienced the same pattern with the ua-parser-js, coa, and rc package takeovers (October–November 2021), where stolen maintainer credentials via credential stuffing were used to publish DanaBot password-stealing trojans and XMRig cryptominers. PyPI, RubyGems, and crates.io have all faced similar credential-theft supply-chain incidents.

Two specific incidents drove the urgency of the NuGet policy change. First, the Nx Console supply-chain compromise (CVE-2026-48027, GHSA-c9j4-9m59-847w) on May 18, 2026: an attacker published a malicious Nx Console VSCode extension version (v18.95.0) after exfiltrating a contributor’s GitHub CLI OAuth token. The theft originated from the upstream TanStack npm compromise (CVE-2026-45321, GHSA-g7cv-rxg3-hmpx) on May 11, 2026, where 84 malicious @tanstack/* packages were published with valid npm provenance. When a Nx contributor ran pnpm install in an external repo, a malicious prepare script executed a 2.3 MB obfuscated credential harvester that exfiltrated the contributor’s gh CLI token from ~/.config/gh/hosts.yml within 74 seconds. The attacker then spent 5+ days with the stolen token deleting CodeQL workflow runs and planting orphan commits before publishing the malicious extension, which was activated approximately 6,000 times in 36 minutes across VS Code and Cursor installations. The root cause chain included four compounding failures: an upstream dependency compromise with valid provenance, a silent minimum-release-age bypass (pnpm 10.14 silently ignored the 7-day release-age policy in .npmrc because the feature only shipped in pnpm 10.16+), gh CLI credentials readable by any local process, and a single-actor publishing pipeline lacking approval gating.

Second, concurrent research by Socket’s Threat Research Team identified five malicious NuGet packages published under the account bmrxntfj that typosquat Chinese .NET UI libraries (AntdUI-derived). The packages — IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32 — carry a .NET Reactor-protected infostealer targeting credentials from 12 Chromium-based browsers, 8 desktop cryptocurrency wallets, 5 browser wallet extensions (MetaMask, TronLink, Phantom, Trust Wallet, Coinbase Wallet), SSH private keys, and cloud service credentials. The payload fires via the CLR module initializer, patches clrjit.dll!getJit to hijack the JIT compiler, and executes a 786 KB MSIL assembly (we4ftg.exe) recovered from live memory dumps. The operator uses version rotation evasion — 219 of 224 total versions carry listed: false, keeping only one version visible at a time while invalidating file-hash-based IOCs. The C2 domain dns-providersa2.com (registered 2026-03-12 via Njalla privacy registrar, hosted at 62.84.102.85 on VDSINA/ASN 216071 in Amsterdam) serves /check (beacon) and /upload (exfiltration) endpoints. Data is staged at C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltration. The packages have accumulated approximately 64,784 total downloads since September 2025 and remain live on NuGet.org.

Microsoft’s recommended alternative to API keys is NuGet Trusted Publishing, launched September 24, 2025. This uses OpenID Connect (OIDC) to let CI/CD workflows authenticate to NuGet.org without storing any long-lived shared secret. The workflow requests a signed, short-lived identity token from the CI/CD platform (GitHub Actions or GitLab); NuGet.org validates the token cryptographically against a policy configured by the package owner (repository, workflow, optional environment details) and issues a single-use temporary API key valid for approximately one hour. Key benefits include no long-lived secrets in repositories or CI/CD secret stores, automatic credential expiration, workload identity validation, and no manual secret rotation. For private GitHub repositories, new policies undergo a 7-day pending activation period to prevent resurrection attacks (where a deleted repository is recreated under the same name by a different owner). Community concerns raised in comments to the announcement include the lack of org-level cross-account support for Trusted Publishing (GitHub issue #10581), the absence of Azure DevOps OIDC support, and the practical pain of 30-day key rotation for teams without CI/CD OIDC support.

The change is part of a broader industry shift toward secure, keyless package publishing aligned with the OpenSSF Securing Software Repositories Working Group’s Trusted Publishers for All Package Repositories initiative. GitHub has proposed a parallel plan for npm that includes deprecating classic tokens, requiring FIDO-based 2FA, limiting granular tokens to 7-day expiration, and expanding trusted publishing to CircleCI (April 2026) and others. NuGet.org’s Trusted Publishing currently supports GitHub Actions and GitLab, with additional CI/CD environments under development. Microsoft has indicated that API key durations may be reduced further in the future as Trusted Publishing adoption grows.

## MITRE ATT&CK

- T1195.001 Compromise Software Dependencies and Development Tools
- T1195.002 Compromise Software Supply Chain
- T1078 Valid Accounts
- T1059.007 JavaScript
- T1543.001 Launch Agent
- T1548.003 Sudo and Sudo Caching
- T1027.005 Indicator Removal from Tools
- T1140 Deobfuscate/Decode Files or Information
- T1685 Disable or Modify Tools
- T1055 Process Injection
- T1552.001 Credentials In Files
- T1552.004 Private Keys
- T1555.005 Password Managers
- T1555.003 Credentials from Web Browsers
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1071.004 DNS

## Sources

- [Microsoft strengthens NuGet supply chain security](https://cybersecuritynews.com/microsoft-strengthens-nuget-supply-chain-security/)
- [Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime](https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/)
- [Trusted Publishing on nuget.org](https://learn.microsoft.com/en-us/nuget/nuget-org/trusted-publishing)
- [Enhanced Security is here with the new Trust Publishing on NuGet.org](https://devblogs.microsoft.com/dotnet/enhanced-security-is-here-with-the-new-trust-publishing-on-nuget-org/)
- [Microsoft reducing NuGet API keys’ lifetime to 30 days](https://www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/)
- [Nx Console v18.95.0 Supply-Chain Compromise Postmortem](https://nx.dev/blog/nx-console-v18-95-0-postmortem)
- [CVE-2026-48027 (Nx Console)](https://nvd.nist.gov/vuln/detail/CVE-2026-48027)
- [GHSA-c9j4-9m59-847w (Nx Console Security Advisory)](https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w)
- [GHSA-g7cv-rxg3-hmpx / CVE-2026-45321 (TanStack Compromise)](https://github.com/tanstack/tanstack/security/advisories/GHSA-g7cv-rxg3-hmpx)
- [5 Malicious NuGet Packages Impersonate Chinese .NET UI Libraries](https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries)
- [Malicious NuGet IR Packages Deliver Credential Stealer](https://corgea.com/research/malicious-nuget-ir-packages-credential-stealer)
- [Our plan for a more secure npm supply chain](https://github.blog/2026-01-our-plan-for-a-more-secure-npm-supply-chain/)
- [Trusted Publishers for All Package Repositories (OpenSSF)](https://repos.openssf.org/trusted-publishers-for-all-package-repositories)
- [NuGet adds support for trusted publishing](https://sdtimes.com/softwaredev/nuget-adds-support-for-trusted-publishing/)
- [npm docs: Trusted publishing for npm packages](https://docs.npmjs.com/trusted-publishing)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1876
