Malicious NuGet, npm Packages Target Developers

Sophisticated NuGet and npm attacks target developers, stealing data and planting backdoors in applications.

  • NuGet campaign exfiltrated ASP.NET Identity data and created backdoors after amassing over 4,500 downloads.
  • Separately, a malicious npm package, ambar-src, was downloaded over 50,000 times before its removal.
  • Both supply chain attacks target developers to compromise the applications they build or the machines they use.

Cybersecurity researchers uncovered a sophisticated attack in February 2026, where four malicious NuGet packages targeted ASP.NET developers through the repository. The packages, downloaded thousands of times, aimed to steal sensitive identity data and manipulate authorization rules within web applications.

- Advertisement -

Published in August 2024 by a user named hamzazaheer, the packages worked in concert to establish a C2 proxy and exfiltrate information. Security researcher Kush Pandya explained the objective was to compromise the applications developers build rather than their machines directly.

Consequently, attackers could gain persistent admin-level access to any deployed application instance. The campaign’s components included a dropper, credential stealers, and a utility for hidden file execution.

Meanwhile, a separate npm campaign was discovered involving the package ambar-src. This malicious code, uploaded on February 13, 2026, exploited preinstall scripts to deliver different payloads based on the operating system, as detailed by Tenable.

This malware downloaded reverse shells for Linux and Windows and a JXA agent called Apfell for macOS. Its mature design suggests it evolved from a previous malicious package, eslint-verify-plugin.

- Advertisement -

Furthermore, the ambar-src package exfiltrated stolen data to a Yandex Cloud domain to blend with legitimate traffic. Tenable warned that any system with the package should be considered fully compromised, as removal does not guarantee all malware is eliminated.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Syracuse Adopts AWS AI Chips on Theta EdgeCloud

Syracuse University will adopt AWS Trainium on Theta EdgeCloud Hybrid for cutting-edge generative AI...

UK Politicians Urge Temporary Ban on Crypto Donations

A UK parliamentary committee has called for a temporary ban on cryptocurrency donations to...

Tokenized US Treasury Market Tops $10.8B Amid Debt Concerns

The tokenized U.S. Treasury market has grown by over $1 billion to exceed $10.8...

AI Spots Critical Bug In Major Ethereum Client

Octane Security's AI tool discovered a high-severity bug in the Nethermind Ethereum client that,...

Elliptic’s Lens Unifies Screening, Cuts Alert Time by 50%

Elliptic has launched a unified screening interface, Lens, combining wallet and transaction analysis to...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!