Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
Four malicious NuGet packages that target ASP.NET web application developers in an attempt to steal confidential information have been found by cybersecurity researchers.
The campaign, which Socket found, manipulates authorization rules to establish permanent backdoors in victim applications and exfiltrates ASP.NET Identity data, such as user accounts, role assignments, and permission mappings.
Below is a list of the package names:
NCryptYo
DOMOAuth2_
IRAOAuth2.0
SimpleWriter_
Between August 12 and August 21, 2024, a person by the name of hamzazaheer published the NuGet packages to the repository. After responsible disclosure, they were removed from the repository, but not before receiving over 4,500 downloads.
The software supply chain security firm claims that ...

