Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Malicious NuGet Packages Attacking ASP.NET Developers to Steal Login Credentials

## Cybersecurity: Malicious NuGet Packages Targeting ASP.NET Developers

Cybersecurity: Malicious NuGet Packages Targeting ASP.NET Developers

A recent supply chain attack has been identified, targeting ASP.NET developers with four malicious NuGet packages designed to steal login credentials and establish persistent backdoors in web applications.

Packages Involved: NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ Publication Date: Between August 12 and 21, 2024 Threat Actor: Operated under the username "hamzazaheer" Downloads: Over 4,500 downloads collectively

The attack deploys deception tactics, where NCryptYo masquerades as a cryptography library similar to the legitimate NCrypto package. The package's DLL, named NCrypt.dll, mimics Windows’ native cryptography provider, and its namespace resembles Microsoft’s cryptography APIs. A static constructor is executed upon assembly load, deploying a hidden proxy on localhost port 7152, relaying traffic to an external server controlled by the attacker.

Other packages, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_, share a byte-identical hardcoded authentication token encoded using GZip compression and custom Base64 substitutions, confirming they originate from the same operator. These packages collect ASP.NET Identity data and route it to the attacker's server.

The package's DLL, named NCrypt.dll, mimics Windows’ native cryptography provider, and its namespace resembles Microsoft’s cryptography APIs.
Amanda Parks · Thehackingpost

NCryptYo utilizes JIT compiler hijacking to obscure its malicious behavior. The .NET runtime typically compiles methods just before execution; however, this package replaces that process with a hook, decrypting the malicious code at runtime, thus evading static analysis. The DLL is protected by .NET Reactor obfuscation, including a 14-day expiry timer and anti-debugging checks.

Verify package names, author identities, and download histories before installation. Monitor network traffic for unusual activity on localhost ports. Implement automated CI/CD pipeline scanning to detect obfuscation markers, static constructor misuse, and embedded encrypted payloads.

Advertisement

Security teams should ensure these measures are in place to mitigate the risk of malicious package installations and protect sensitive data from unauthorized access.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories