Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
ID: 3bb3d44b-ff2b-5fbe-8263-5172bd9054fe
STIX ID: report--3bb3d44b-ff2b-5fbe-8263-5172bd9054fe
Feed Name: The Hacker News
Cybersecurity researchers uncovered a supply-chain campaign consisting of four malicious NuGet packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) designed to target ASP.NET developers: NCryptYo acts as a stage-1 dropper installing a localhost proxy that relays to a dynamic external C2, while the companion packages exfiltrate ASP.NET Identity data and inject authorization rules to create persistent backdoors in deployed applications; additionally the report describes a separate malicious npm package (ambar-src) that uses install hooks to deploy multi-platform payloads and exfiltrate data to a cloud domain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
