Siemens is aware of the nine malicious NuGet packages reported recently by Socket researchers. Siemens has investigated these NuGet packages aimed at disrupting industrial operations.
The malicious nature of the software seems to be only relevant to yet unknown, non-Siemens software which includes these packages. If this software implements a client to communicates with Siemens PLCs via legacy PUT/GET protocol, the manipulations can randomly close the connection to the device and/or cause silent failures when writing data to the PLC. The integrity of the PLC software is not affected.
Read the full news article