logo

Malicious NuGet Packages Target Browser Credentials, SSH Keys, and Crypto Wallets

ID: 20cc68c0-dcec-516e-a5ca-9702f0031f52

STIX ID: report--20cc68c0-dcec-516e-a5ca-9702f0031f52

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Tushar Subhra Dutta

...
...

This report describes a persistent supply-chain campaign where an actor publishing under the NuGet account "bmrxntfj" released five malicious packages built atop legitimate .NET libraries; the packages use a .NET module initializer and JIT hooking to deploy a second-stage infostealer (we4ftg.exe) that exfiltrates browser credentials, crypto wallet data, SSH keys, Outlook/Steam credentials, and files to a C2 infrastructure, with ~64,784 downloads and extensive IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.