home.social

#nuget — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #nuget, aggregated by home.social.

fetched live
  1. I just released version 0.9 of ConsoleRenderer!

    This version increases performance for sparsely populated screens by a significant margin, thanks to @micutio!

    This version also drops support for .NET 8 in favor of .NET 10, which is the latest LTS version.

    The previous version is still very stable, so if you you depend on ConsoleRenderer and haven't moved your project to .NET 10, you can still use that without issue.

    nuget.org/packages/ConsoleRend

  2. I just released version 0.9 of ConsoleRenderer!

    This version increases performance for sparsely populated screens by a significant margin, thanks to @micutio!

    This version also drops support for .NET 8 in favor of .NET 10, which is the latest LTS version.

    The previous version is still very stable, so if you you depend on ConsoleRenderer and haven't moved your project to .NET 10, you can still use that without issue.

    nuget.org/packages/ConsoleRend

    #nuget #rendering #terminal #foss

  3. 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

    Pulse ID: 6a585deae380be77ce7e1512
    Pulse Link: otx.alienvault.com/pulse/6a585
    Pulse Author: Tr1sa111
    Created: 2026-07-16 04:28:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NuGet #OTX #OpenThreatExchange #Windows #bot #Tr1sa111

  4. 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

    Pulse ID: 6a585deae380be77ce7e1512
    Pulse Link: otx.alienvault.com/pulse/6a585
    Pulse Author: Tr1sa111
    Created: 2026-07-16 04:28:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #NuGet #OTX #OpenThreatExchange #Windows #bot #Tr1sa111

  5. 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

    Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

    Pulse ID: 6a57b568d98a7ae03ccd6071
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:29:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #DNS #GitHub #Google #HTTP #HTTPS #HuggingFace #InfoSec #NET #NuGet #OTX #OpenThreatExchange #RAT #RCE #Russia #Telegram #Windows #bot #AlienVault

  6. 11 Malicious NuGet Tools Pose as Game Cheats to Drop a Windows Host-Surveillance Payload

    Eleven malicious NuGet packages distributed as .NET command-line tools masquerade as game utilities and cheats for popular games including Albion Online, GTA5RP, GrandRP, and Throne and Liberty. Each package functions as a first-stage downloader that uses DNS-over-HTTPS to bypass local controls, requests UAC elevation to resync system time, and fetches a second-stage PyInstaller payload named pepesoft.exe from GitHub and Hugging Face under username pepegit666. The payload binds to hardware fingerprints, enforces licensing through Google Sheets telemetry, honors remote ban-lists, and in three variants exposes Telegram bot commands enabling screenshot capture and remote control. All packages share identical AWS credentials and mutex identifiers, linking them to a single Russian-speaking operator running a commercial game-automation service marketed through pepesoft.ru and Telegram channel pepesoft777.

    Pulse ID: 6a57b568d98a7ae03ccd6071
    Pulse Link: otx.alienvault.com/pulse/6a57b
    Pulse Author: AlienVault
    Created: 2026-07-15 16:29:28

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #CyberSecurity #DNS #GitHub #Google #HTTP #HTTPS #HuggingFace #InfoSec #NET #NuGet #OTX #OpenThreatExchange #RAT #RCE #Russia #Telegram #Windows #bot #AlienVault

  7. If you're a C# #developer and need some helpful generalized/reusable code, you can check out an offshoot of my big project called #CapyKit.

    git.jordanwages.com/wagesj45/C

    Documentation: capykit.happycapy.net/

    Available in #nuget via #selfhosted #Foregejo repository. Or build it yourself.

  8. If you're a C# #developer and need some helpful generalized/reusable code, you can check out an offshoot of my big project called #CapyKit.

    git.jordanwages.com/wagesj45/C

    Documentation: capykit.happycapy.net/

    Available in #nuget via #selfhosted #Foregejo repository. Or build it yourself.

  9. #TIL Nowadays #NuGET replaces #API keys with what they call trusted publishing which is kind of oAuth where CI runs (currently only #GitHub actions, it seems) ask for a short-lived token, receive it and publish a package. Reason number 42 for me to stay on gitHub. #DotNet

  10. #TIL Nowadays #NuGET replaces #API keys with what they call trusted publishing which is kind of oAuth where CI runs (currently only #GitHub actions, it seems) ask for a short-lived token, receive it and publish a package. Reason number 42 for me to stay on gitHub. #DotNet

  11. Just blogged: Follow-up to my 2021 console stack post: templates scaffold well, but shared glue code drifts when you maintain many CLI tools.

    Now I use Devlead.Console.Template plus the Devlead.Console source package. Scaffold once, update bootstrap via NuGet. Partial Program hooks for your commands and DI.

    devlead.se/posts/2026/2026-06-

    #dotnet #csharp #oss #nuget

  12. Just blogged: Follow-up to my 2021 console stack post: templates scaffold well, but shared glue code drifts when you maintain many CLI tools.

    Now I use Devlead.Console.Template plus the Devlead.Console source package. Scaffold once, update bootstrap via NuGet. Partial Program hooks for your commands and DI.

    devlead.se/posts/2026/2026-06-

    #dotnet #csharp #oss #nuget

  13. File-based apps в .NET 10

    Для небольших скриптов на C# долгое время приходилось создавать полноценный проект даже ради нескольких строк кода. В.NET 10 появилась поддержка file‑based apps — теперь приложение можно запускать и публиковать прямо из одного.cs‑файла. Разбираемся, как это работает и где новый подход действительно полезен.

    habr.com/ru/companies/otus/art

    #NET_10 #C# #filebased_apps #Native_AOT #ASPNET_Core #minimal_API #NuGet #CLI_утилиты #автоматизация #скрипты

  14. I really wish #NuGet had an SBOM tab, i.e., #dotnet tools show "This package has no dependencies." which, from a NuGet package point of view, is true, but .NET tools can have plenty of dependencies, they're just bundled. Dependencies aren't just a package graph; they're acknowledgement and risk.

  15. I really wish #NuGet had an SBOM tab, i.e., #dotnet tools show "This package has no dependencies." which, from a NuGet package point of view, is true, but .NET tools can have plenty of dependencies, they're just bundled. Dependencies aren't just a package graph; they're acknowledgement and risk.

  16. Just released the StyloExtract packages nuget.org/packages?q=styloextr

    Really for internal use but someone might find them useful.
    It's an adaptive HTML to (AI Friendly, structural) Markdown converter designed for extensibility and AoT compatibility.

    It's the basis of a future StyloBot feature where it will auto generate any upstream page to markdown for AI scrapers automatically. This lets it be FAST!

    #nuget #stylobot

  17. Just released the StyloExtract packages nuget.org/packages?q=styloextr

    Really for internal use but someone might find them useful.
    It's an adaptive HTML to (AI Friendly, structural) Markdown converter designed for extensibility and AoT compatibility.

    It's the basis of a future StyloBot feature where it will auto generate any upstream page to markdown for AI scrapers automatically. This lets it be FAST!

    #nuget #stylobot

  18. Changes to NuGet package ids

    nuget.org now requires new package IDs to use only ASCII letters, digits, dots, and dashes, similar to the conventions used by npm, PyPI, and other major registries. Existing packages and existing IDs remain available.

    Enforced for new packages, and from 15th July for existing packages.

    github.com/NuGet/Announcements

    #dotnet #nuget

  19. Changes to NuGet package ids

    nuget.org now requires new package IDs to use only ASCII letters, digits, dots, and dashes, similar to the conventions used by npm, PyPI, and other major registries. Existing packages and existing IDs remain available.

    Enforced for new packages, and from 15th July for existing packages.

    github.com/NuGet/Announcements

    #dotnet #nuget

  20. Opening #NuGet packages & decompiling assemblies in them was possible for a long time. Net-new will be a search & download capability for arbitrary NuGet feeds #ilspy #comingsoon

  21. Opening #NuGet packages & decompiling assemblies in them was possible for a long time. Net-new will be a search & download capability for arbitrary NuGet feeds #ilspy #comingsoon

  22. Rust внутри .NET: как упаковать native-библиотеку в один NuGet-пакет

    FFI, P/Invoke, EmbeddedResource, DllImportResolver и кроссплатформенная доставка без ручного копирования .dll , .so и .dylib . Когда .NET-коду нужно вызвать Rust-библиотеку, первый прототип обычно заводится быстро: Rust собирается как cdylib ; функции экспортируются через extern "C" ; C# вызывает их через DllImport ; результат возвращается через указатель.

    habr.com/ru/articles/1043276/

    #dotnet #rust #ffi #invoke #nuget #nativelibrary #dllimportresolver

  23. github.com/dennisdoomen/dotnet - #dotNET library starter kit is a bunch of dotnet new templates to quickly get you started building high-quality #NuGet packages.

  24. github.com/dennisdoomen/dotnet - #dotNET library starter kit is a bunch of dotnet new templates to quickly get you started building high-quality #NuGet packages.

  25. KeyboardHook: кроссплатформенный глобальный перехват клавиатуры и мыши для .NET

    Рассказываю, как написал кроссплатформенную .NET-библиотеку для глобального перехвата клавиатуры и мыши. Под капотом: WH_KEYBOARD_LL на Windows, CGEventTap на macOS и polling через XQueryKeymap на Linux. Один интерфейс, три реализации, ноль внешних зависимостей.

    habr.com/ru/articles/1040932/

    #nuget #c# #net #windows #linux #macos #global_hooks #keyboardhooker #crossplatform

  26. #Nuget: Malicious NuGet packages mimicked trusted .NET libraries to steal credentials, key crypto wallets.
    Packages:

    IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32

    included an infostealer #malware:
    👇
    gbhackers.com/malicious-nuget-

  27. #Nuget: Malicious NuGet packages mimicked trusted .NET libraries to steal credentials, key crypto wallets.
    Packages:

    IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32

    included an infostealer #malware:
    👇
    gbhackers.com/malicious-nuget-

  28. In about one hour, combining the powers of Native AOT and System.CommandLine, we will turn Inspector Roslyn into a standalone CLI tool.

    2026-04-22 (Wednesday)
    at 17:00 UTC

    #2codeOrNot2code #dotnet #CSharp #Roslyn #NuGet

    youtube.com/watch?v=DAyZ_6KvpiM