The Moq NuGet SponsorLink Incident

Updated 5 Oct 2026 · Incident date 8 Aug 2023 · NuGet

PackageMoq 4.18.4 -> 4.20.0 and 4.20.1 (reverted in 4.20.2)
Filethe new Devlooped.SponsorLink dependency - an obfuscate...

In August 2023, versions 4.20.0 and 4.20.1 of the Moq NuGet package added a dependency named SponsorLink. During a build, it read the developer's git email address, hashed it and sent the hash to a remote server. Version 4.20.2 removed the dependency.

This was not an outside attacker. The package maintainer added it. It still matters because the new dependency ran code on developer machines with no opt-out and no notice.

What happened

A trusted package started collecting data from developers when they compiled. According to Checkmarx, version 4.20.0 and 4.20.1 came out on 8 August 2023, and developers reported the behavior on Reddit and GitHub on 9 August. The sub-dependency was Devlooped.SponsorLink.

Checkmarx and Snyk describe the behavior:

  1. It ran git config --get user.email in a separate process.
  2. It hashed the email with SHA-256.
  3. It sent the result to https://cdn.devlooped.com/sponsorlink. Snyk describes an HTTP HEAD request with the hash in the URL, sent to Azure blob storage, and a check with the SponsorLink service.

The code ran automatically at build time as a .NET analyzer. It had no setting to turn it off. It skipped CI systems when it saw variables such as CI, TF_BUILD, TRAVIS and JENKINS_URL. The code was obfuscated and closed source.

BleepingComputer quotes the maintainer, Daniel Cazzulino, who said the real email is never sent and that the hash uses SHA-256 then Base62 encoding. Full emails were stored only after a user installed the SponsorLink GitHub app. Developers raised privacy concerns, including GDPR. The maintainer released 4.20.2, which rolled the change back.

Vigilance compares the version you trust with the new one. Moq 4.20.0 added a package reference that brought in a build-time analyzer with network and process access. Vigilance reports the file that gained that capability. See the scan block below.

Affected versions

Snyk reports that 4.20.0 had 10,356 downloads in under 24 hours. Snyk and BleepingComputer name projects that depend on Moq, such as Microsoft PowerToys and Jellyfin.

Indicators of compromise

How to check

List the Moq version and the SponsorLink package in each solution.

dotnet list package --include-transitive | grep -iE "moq|sponsorlink"

Any Moq 4.20.0 or 4.20.1, or any Devlooped.SponsorLink line, means the build possibly sent the hash. Also search the NuGet cache for the package.

ls ~/.nuget/packages | grep -i sponsorlink

What to do now

  1. Move to Moq 4.20.2 or a version before 4.20.0, such as 4.18.4. Check that Devlooped.SponsorLink is gone from the lockfile.
  2. Delete the SponsorLink package from the NuGet cache.
  3. Block Moq 4.20.0 and 4.20.1 in your package feed.
  4. Decide with your privacy officer whether a hashed email counts as personal data in your case.
  5. Pin versions and review new transitive dependencies before you update.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Moq-4.18.4 --new Moq-4.20.0
files scanned: 22

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.nuspec
           It now downloads from the internet and runs a hidden, encoded command. It did not before.

Frequently asked questions

Which Moq versions contain SponsorLink?

Moq 4.20.0 and 4.20.1 contain SponsorLink. Version 4.20.2 removed it, and 4.18.4 is the last version before the change.

What data did the Moq SponsorLink code send?

It read the git email address, hashed it with SHA-256 and sent the hash to a remote SponsorLink endpoint during the build. The maintainer states that the plain email was not sent.

Sources

  1. checkmarx.com/blog/popular-nuget-package-moq-silently-exfiltrates-user-data-to-cloud-service/
  2. snyk.io/blog/moq-package-exfiltrates-user-emails/
  3. bleepingcomputer.com/news/security/popular-open-source-project-moq-criticized-for-quietly-collecting-data/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free