NuGet package maintainers can now receive financial support from their users by adding sponsorship URLs to their packages.
An attack on the NuGet package registry shows how advanced open-source software supply chain attacks have become.
Malicious NuGet package mimicking Nethereum stole crypto wallet keys using homoglyph tricks and fake downloads.