Four malicious NuGet packages that target ASP.NET web application developers in an attempt to steal confidential information have been found by cybersecurity researchers.
The campaign, which Socket found, manipulates authorization rules to establish permanent backdoors in victim applications and exfiltrates ASP.NET Identity data, such as user accounts, role assignments, and permission mappings.
Below is a list of the package names:
- NCryptYo
- DOMOAuth2_
- IRAOAuth2.0
- SimpleWriter_
Between August 12 and August 21, 2024, a person by the name of hamzazaheer published the NuGet packages to the repository. After responsible disclosure, they were removed from the repository, but not before receiving over 4,500 downloads.
The software supply chain security firm claims that NCryptYo functions as a first-stage dropper, setting up a local proxy on localhost read more about Malicious NuGet Packages Stole ASP.NET Data npm Package Dropped Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
