Highly Evasive NuGet Supply Chain Attack Hijacks 65,000 .NET Build Servers
ID: f05bc2d1-4dce-512e-accd-41fb4f7dcacd
STIX ID: report--f05bc2d1-4dce-512e-accd-41fb4f7dcacd
Feed Name: securityonline.info
Socket’s Threat Research Team uncovered a highly sophisticated software supply-chain campaign delivering malicious NuGet packages (IR.*) that have been downloaded ~65,000 times; the payload executes via the .NET module initializer, patches the CLR JIT to run obfuscated code cross-platform, harvests credentials, browser and hardware wallets, SSH keys and Steam data, stages exfiltrated data to a OneDrive-like path, and POSTs it to a tracked C2 domain while evading detection through extensive unlisted version rotation and unique cryptographic linking to other malware families.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
