Tag: Malicious NuGet Packages

Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
News

Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware

Four malicious NuGet packages that target ASP.NET web application developers in an attempt to steal confidential information have been found by cybersecurity researchers. The campaign, which Socket found, manipulates authorization rules to establish permanent backdoors in victim applications and exfiltrates ASP.NET Identity data, such as user accounts, role assignments, and permission mappings. Below is a list of the package names: NCryptYo DOMOAuth2_ IRAOAuth2.0 SimpleWriter_ Between August 12 and August 21, 2024, a person by the name of hamzazaheer published the NuGet packages to the repository. After responsible disclosure, they were removed from the repository, but not before receiving over 4,500 downloads. The software supply chain security firm claims that ...
Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation
News

Hidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation

Nine malicious NuGet packages have been found to be able to disrupt industrial control systems and interfere with database operations by dropping time-delayed payloads. The packages were released in 2023 and 2024 by a user known as "shanhai666" and are intended to execute malicious code following particular trigger dates in August 2027 and November 2028, according to software supply chain security firm Socket. Together, 9,488 downloads of the packages were made. According to security researcher Kush Pandya, the most dangerous package, Sharp7Extend, targets industrial PLCs with dual sabotage mechanisms: immediate random process termination and silent write failures that start 30 to 90 minutes after installation, impacting safety-critical systems in manufacturing environments. Belo...
Malicious NuGet Packages Caught Distributing SeroXen RAT Malware
News

Malicious NuGet Packages Caught Distributing SeroXen RAT Malware

Researchers studying cybersecurity have discovered a fresh batch of dangerous packages that were uploaded to the NuGet package management via a little-known malware distribution technique. ReversingLabs, a software supply chain security organization, linked a number of rogue NuGet packages that were seen to be distributing the remote access trojan SeroXen RAT to the campaign, which it described as coordinated and ongoing since August 1, 2023. Karlo Zanki, a reverse engineer at ReversingLabs, stated in a report published with The Hacker News that "the threat actors behind it are tenacious in their desire to plant malware into the NuGet repository, and to continuously publish new malicious packages read more Malicious NuGet Packages Caught Distributing SeroXen RAT Malware. Get up t...