Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C software development kit for Sicoob one of Brazils largest cooperative financial systems to siphon client IDs and PFX certificates According to Socket versions 200 through 204 of SicoobSdk contain functionality to exfiltrate sensitive information including PFX certificates that are used to