
Research
/Security News
9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Sleek, intuitive, and powerful front-end framework for faster and easier web development.
Build responsive, mobile-first projects on the web
with the first front-end component library in Metro Style.
[!IMPORTANT]
License and Premium Features
This project is licensed under the MIT license. In addition, SUPPORT PACK is available for an annual subscription on Korzh.com. SUPPORT PACK includes an Extra time for priority support by email and other options.
All contributions are welcome. Learn more about how you can contribute to this project here.
[!NOTE] Before you create Pull Request, you must sign CLA!
Please click Documentation and Demo.
Metro UI releases frequently. I'm creating release when there are significant bug fixes, new APIs, or components. The usual frequency of release of the new version is one week on Sundays.
Long-term support of older versions of Metro UI doesn't currently exist. If your current version of Metro UI works for you, you can stay on it for as long as you would like. If you want to make use of new features as they come in, you should upgrade to a newer version.
![]() | ![]() | ![]() | ![]() | ![]() |
|---|---|---|---|---|
| Latest 2 ✔ | Latest 2 ✔ | Latest 2 ✔ | Latest 2 ✔ | Latest 2 ✔ |
Metro-UI-CSS-4 - Repository, DocumentationMetro-UI-CSS-3 - Repository, DocumentationMetro-UI-CSS-2 - Repository, DocumentationMetro-UI-CSS-1 - RepositoryThanks to all. Special thanks to all those who financially supported the project.
If you like this project, please consider supporting it by:
serhii@pimenov.com.ua.Copyright (c) 2012-2025 by Serhii Pimenov. All Rights Reserved.
FAQs
Unknown package
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.

Security News
Learn the essential steps every developer should take to stay secure on npm and reduce exposure to supply chain attacks.