Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Four Malicious NuGet Packages Target ASP.NET Developers With JIT Hooking and Credential Exfiltration

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
3,466
Company Posts That Month
33
Language
English
Hacker News Points
-
Post removed?
No
Summary

Socket's Threat Research Team identified a sophisticated NuGet supply chain attack targeting ASP.NET web application developers through four malicious packages, including NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_, all published by the threat actor hamzazaheer. The attack involves a multi-stage payload, with NCryptYo serving as a stage-1 dropper that establishes a local proxy on localhost:7152, enabling the exfiltration of ASP.NET Identity data and the creation of persistent backdoors via manipulated authorization rules. The packages, which have amassed over 4,500 downloads, employ various obfuscation techniques, including typosquatting the legitimate NCrypto package, to evade detection by security vendors. The threat actor's shared infrastructure is evident through byte-identical authentication tokens across the packages, which are built on a consistent system environment and share metadata quirks suggesting common authorship. The attack chain activates when developers install these packages, leading to unauthorized access to applications by exploiting the compromised authorization layer during development. Socket's AI Scanner has initiated takedown requests and offers defense mechanisms against such attacks, including dependency audits, CI/CD scanning, and behavioral monitoring to mitigate potential supply chain threats in production environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 1 1,009 253 106 +42%
MCP 1 3,346 363 139 +19%
Real-time 1 5,046 1,089 214 +11%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.