The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-076-01