logo

Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware

ID: 3bb3d44b-ff2b-5fbe-8263-5172bd9054fe

STIX ID: report--3bb3d44b-ff2b-5fbe-8263-5172bd9054fe

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers uncovered a supply-chain campaign consisting of four malicious NuGet packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) designed to target ASP.NET developers: NCryptYo acts as a stage-1 dropper installing a localhost proxy that relays to a dynamic external C2, while the companion packages exfiltrate ASP.NET Identity data and inject authorization rules to create persistent backdoors in deployed applications; additionally the report describes a separate malicious npm package (ambar-src) that uses install hooks to deploy multi-platform payloads and exfiltrate data to a cloud domain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.