Four Malicious NuGet Packages Target ASP.NET Developers With...
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Socket's Threat Research Team uncovered a coordinated NuGet supply chain attack involving four malicious packages targeting ASP.NET developers. The campaign uses NCryptYo as a typosquatted dropper (mimicking the legitimate NCrypto package) that installs JIT compiler hooks to decrypt and deploy a stage-2 localhost proxy on port
Table of contents
Campaign Linkage: Shared Infrastructure and Build Artifacts #NCryptYo: Obfuscated Dropper #Two-Stage Architecture #DOMOAuth2_: Credential Harvesting #IRAOAuth2.0: Hardcoded-Only Credential Channel #SimpleWriter_: File Drop and Process Execution #Attack Chain and Impact #Outlook and Recommendations #MITRE ATT&CK #Indicators of Compromise (IOCs) #Sort: