Malicious NuGet Packages Target Browser Credentials, SSH Keys, and Crypto Wallets
ID: 20cc68c0-dcec-516e-a5ca-9702f0031f52
STIX ID: report--20cc68c0-dcec-516e-a5ca-9702f0031f52
Feed Name: cybersecurityNews.com
Threat Score
This report describes a persistent supply-chain campaign where an actor publishing under the NuGet account "bmrxntfj" released five malicious packages built atop legitimate .NET libraries; the packages use a .NET module initializer and JIT hooking to deploy a second-stage infostealer (we4ftg.exe) that exfiltrates browser credentials, crypto wallet data, SSH keys, Outlook/Steam credentials, and files to a C2 infrastructure, with ~64,784 downloads and extensive IoCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
