Keeper.SecretsManager.AWSKeyManagement
0.0.0-security-research
dotnet add package Keeper.SecretsManager.AWSKeyManagement --version 0.0.0-security-research
NuGet\Install-Package Keeper.SecretsManager.AWSKeyManagement -Version 0.0.0-security-research
<PackageReference Include="Keeper.SecretsManager.AWSKeyManagement" Version="0.0.0-security-research" />
<PackageVersion Include="Keeper.SecretsManager.AWSKeyManagement" Version="0.0.0-security-research" />
<PackageReference Include="Keeper.SecretsManager.AWSKeyManagement" />
paket add Keeper.SecretsManager.AWSKeyManagement --version 0.0.0-security-research
#r "nuget: Keeper.SecretsManager.AWSKeyManagement, 0.0.0-security-research"
#:package Keeper.SecretsManager.AWSKeyManagement@0.0.0-security-research
#addin nuget:?package=Keeper.SecretsManager.AWSKeyManagement&version=0.0.0-security-research&prerelease
#tool nuget:?package=Keeper.SecretsManager.AWSKeyManagement&version=0.0.0-security-research&prerelease
Security research placeholder
This is not a Keeper Security product and it contains no code.
What this is
This package ID is named by a dotnet add package command in Keeper Secrets Manager
documentation on docs.keeper.io, but the ID had never been published to nuget.org. Because the
Keeper. ID prefix is not reserved on NuGet, the ID was claimable by any third party. Anyone who
published it would have been installed by developers and AI coding agents following Keeper's own
official integration documentation.
This placeholder holds the ID so that it cannot be claimed maliciously while the issue is remediated.
What it does
Nothing. By design.
It ships no assembly (IncludeBuildOutput=false, so there is no lib/ folder), no MSBuild
.props or .targets, no install or restore hooks, no content files, no dependencies, and no
telemetry or callback of any kind. Installing it adds a package reference that resolves and
supplies nothing. It cannot execute code because it contains none.
Why it exists rather than being left open
Dependency confusion is the absence of a package, not the presence of one. The exposure lasts exactly as long as the ID is unclaimed. Leaving it open while the report was triaged would have meant relying on nobody else noticing.
Note for developers who reached this by following the documentation
If dotnet add package brought you here, the .NET integration module you are looking for is not
published under this ID. Please check Keeper's current documentation or contact Keeper Security
support for the supported .NET installation path. Do not depend on this package.
Be aware that this placeholder resolves silently rather than failing, which is a change from the
previous behaviour where the command returned There are no versions available for the package.
That error was a clearer signal and its loss is a deliberate tradeoff, accepted because an
unclaimed ID under a secrets-management vendor's namespace is the worse of the two risks.
For Keeper Security
This ID is yours on request. Transfer, unlisting or deletion will be actioned immediately at your request, with no conditions. Reach me through the Bugcrowd submission this accompanies, or through the Bugcrowd program contact.
Researcher: gh0stfqce (Bugcrowd)
Bugcrowd submission: 2324937a-b90f-442c-97da-44ca989be275
Version scheme: 0.0.0-security-research, prerelease, so it is never selected by a wildcard or
floating version range.
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.0.0-security-research | 96 | 9/7/2026 |