.NUPKG

NUPKG File

NuGet Package
Ask a question
QUICK ANSWER

A .nupkg file is a NuGet package - the standard way .NET libraries are distributed for the .NET ecosystem. It is a ZIP archive holding compiled .dll files and a .nuspec metadata manifest. You rarely open one by hand; Visual Studio and the "dotnet add package" command handle installation automatically. To inspect the contents, use NuGet Package Explorer or rename the file to .zip and open it with 7-Zip.

Developer: Microsoft / .NET Foundation (NuGet) Category: Developer Files Open standard MIME: application/octet-stream
OPENS ON Windows macOS Linux
Related: .DO · .MD · .HEX · .XSD

On this page

19k+ extensions indexed
Last reviewed Jun 20, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the NUPKG file format?

A .nupkg file stores a standardized NuGet package used to distribute .NET libraries, tools, or application components. Underneath, .nupkg is a ZIP archive structured according to Open Packaging Conventions (OPC) - the same container family as .docx - and contains compiled .dll assemblies, a .nuspec metadata manifest, a [Content_Types].xml descriptor, and lib/ folders that organize assemblies by target framework moniker (e.g. net8.0, netstandard2.0).

What is NuGet?

NuGet is the package manager for the Microsoft .NET development platform, now stewarded by the .NET Foundation. It has been bundled by default with Visual Studio since the release of Visual Studio 2012 and is also available as a standalone CLI. NuGet supports .NET Framework, .NET Standard, and all modern .NET releases.

How are .nupkg files generated?

NuGet packages can be generated from a project folder using the dotnet pack command (the modern cross-platform approach) or the legacy nuget pack CLI. When using dotnet pack, package metadata is read directly from the .csproj project file, so a separate .nuspec manifest is no longer required - though one can still be supplied for advanced scenarios. The output is a .nupkg archive ready for distribution.

How to share a NuGet package?

The most popular way of sharing .nupkg files is publishing them to the nuget.org web platform. After registering an account, users upload their .nupkg file and provide a short description; each package undergoes automatic validation before being indexed and made available for download. Private feeds hosted on Azure Artifacts, GitHub Packages, or self-hosted servers are also common in enterprise environments. Companion .snupkg symbol packages can be published alongside a .nupkg to enable source-stepping in debuggers.

Security & safety

RISK: MEDIUM

A .nupkg is data, not directly executable, but installing a package runs its code in your build and apps, so the supply-chain risk is real: malicious or typosquatted packages on nuget.org have been used to ship malware, and a package's tools/ install scripts or MSBuild targets can run during restore/build. Install packages only from trusted authors, watch for typosquatted ids, prefer packages with many downloads and source links, and consider signed packages and lock files. Merely inspecting a .nupkg by unzipping it is safe - the risk comes from installing and building against it.

Format details

in a nutshell
FULL NAMENuGet Package
DEVELOPERMicrosoft / .NET Foundation (NuGet)since 2010 (NuGet 1.0)
MIME TYPEapplication/octet-stream
TYPEZIP-based package archive (Open Packaging Conventions) containing .NET libraries + metadata
STANDARDOpen · royalty-free
MAGIC BYTES · FILE SIGNATURE
OFFSET
00010203
HEX
504B0304
ASCII
PK··
A .nupkg is a ZIP archive (Open Packaging Conventions, the same container family as .docx). Distinguish it from a plain ZIP by its internal layout: a .nuspec manifest at the root, a [Content_Types].xml, _rels/ and package/ OPC folders, and lib/ folders holding the .dll assemblies per target framework. The signed-package variant (.snupkg holds symbols) is the same container.

Programs that open NUPKG files

Windows4 apps
NuGet Package Explorer Open-source Install from the Microsoft Store (or Chocolatey), then File > Open and pick the .nupkg - or open one straight from a feed like nuget.org. Shows metadata on the right, contents on the left.
Visual Studio (NuGet Package Manager) Freemium Don't open the file directly - install the package into a project via Manage NuGet Packages, or add a local folder as a package source for an offline .nupkg.
dotnet CLI / NuGet CLI Free 'dotnet add package <id>' to install, 'dotnet pack' to create, 'dotnet nuget push' to publish. Inspect locally with 'nuget' or by extracting the ZIP.
7-Zip / Windows Explorer Open-source Rename the .nupkg to .zip (or open directly in 7-Zip) to browse/extract the .nuspec and DLLs without any NuGet tooling.
macOS1 app
NuGet Package Explorer (web) / dotnet CLI Open-source Use the web version of NuGet Package Explorer (nuget.info) to inspect a package, or the dotnet CLI ('dotnet add package', 'dotnet pack'). Unzip to browse contents.
Linux1 app
dotnet CLI Open-source 'dotnet add package <id>' / 'dotnet pack'. Inspect by unzipping ('unzip pkg.nupkg') or via the nuget.info web explorer.

Technical details

deep spec
Container formatZIP (Open Packaging Conventions / OPC) - same container family as .docx and .xlsx
Magic bytes`50 4B 03 04` ("PK") - standard ZIP local file header at offset 0
MIME type`application/octet-stream`
Internal manifest`.nuspec` XML file at the package root; declares Id, Version, Authors, dependencies, and target frameworks
Required OPC structure`[Content_Types].xml`, `_rels/` folder, and at least one `.nuspec` manifest
Assembly path convention`lib/<TFM>/` folders - e.g. `lib/net8.0/`, `lib/netstandard2.0/` - one per target framework moniker
Build tools`dotnet pack` (SDK-style projects, cross-platform) or `nuget pack` (legacy NuGet CLI)
Public registrynuget.org - over 500 000 unique package IDs; packages pass automated validation before indexing
Symbol companion format`.snupkg` - separate archive holding `.pdb` symbol files for source-level debugging
Package signingX.509 certificate signatures (author and repository); clients verify signatures on install
Target framework support.NET Framework, .NET Standard, .NET 5-9 and later; multi-targeting supported in a single `.nupkg`
Version schemeSemantic Versioning 2.0 (SemVer 2.0); pre-release labels supported (e.g. `-alpha`, `-rc.1`)
Package cache location`%USERPROFILE%\.nuget\packages\` on Windows; `~/.nuget/packages/` on Linux and macOS
Dependency resolutionFull transitive dependency graph resolved at `dotnet restore`; optional lock file `packages.lock.json` for reproducible builds
Released2010 (NuGet 1.0)
Open standardYes · royalty-free
Specificationlearn.microsoft.com

NUPKG conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with NUPKG files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about NUPKG files.

Frequently asked questions

What is a .nupkg file?
It's a NuGet package - the standard bundle used to distribute .NET libraries. It's a ZIP archive containing compiled .dll files and a .nuspec metadata manifest. Visual Studio and the dotnet CLI install it into projects; you rarely open it by hand.
How do I open a .nupkg file?
To inspect it, use NuGet Package Explorer (Microsoft Store, or nuget.info in a browser), or rename it to .zip and open with 7-Zip/Windows Explorer. To USE it, install it into a project with Visual Studio's NuGet manager or 'dotnet add package'.
Is a .nupkg the same as a ZIP file?
Yes, technically - it's a ZIP using Microsoft's Open Packaging Conventions. Rename it to .zip to extract the .nuspec and DLLs. The .nupkg extension just tells NuGet tooling what it is.
How do I install a .nupkg from a local file?
Add the folder containing it as a NuGet package source (Visual Studio > NuGet settings, or a nuget.config), then install the package by id. From the CLI you can also 'dotnet add package <id> --source <folder>'.
Does a .nupkg contain source code?
Usually no - it contains compiled assemblies (DLLs). The old 'source code package' label is misleading. Source and debug symbols ship in a separate symbol package, the .snupkg.
How do I create a .nupkg?
Run 'dotnet pack' on your project (it reads metadata from the .csproj), or 'nuget pack yourpackage.nuspec'. The .nupkg lands in bin/Release; publish it with 'dotnet nuget push'.

References

1Microsoft Learn - What is NuGet and what does it do?learn.microsoft.com
2Microsoft Learn - .nuspec referencelearn.microsoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.EXEWindows Executable (Portable Executable)
4.PARTPartial Download File
5.DATProgram Data File (generic)
6.BINCD/DVD Disc Image (BIN/CUE)
7.RPMSGRestricted Permission Message
8.MDMarkdown Document
9.TXTPlain Text File
10.TMPTemporary File

Related extensions

.DOStata Do-File
.MDMarkdown Document
.HEXIntel HEX File
.XSDXML Schema Definition
.MAPSource Map (JavaScript / CSS)
.CONFIGConfiguration File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z