BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious NuGet, npm Packages Target Developers

Sophisticated NuGet and npm attacks target developers, stealing data and planting backdoors in applications.

  • NuGet campaign exfiltrated ASP.NET Identity data and created backdoors after amassing over 4,500 downloads.
  • Separately, a malicious npm package, ambar-src, was downloaded over 50,000 times before its removal.
  • Both supply chain attacks target developers to compromise the applications they build or the machines they use.

Cybersecurity researchers uncovered a sophisticated attack in February 2026, where four malicious NuGet packages targeted ASP.NET developers through the repository. The packages, downloaded thousands of times, aimed to steal sensitive identity data and manipulate authorization rules within web applications.

- Advertisement -

Published in August 2024 by a user named hamzazaheer, the packages worked in concert to establish a C2 proxy and exfiltrate information. Security researcher Kush Pandya explained the objective was to compromise the applications developers build rather than their machines directly.

Consequently, attackers could gain persistent admin-level access to any deployed application instance. The campaign’s components included a dropper, credential stealers, and a utility for hidden file execution.

Meanwhile, a separate npm campaign was discovered involving the package ambar-src. This malicious code, uploaded on February 13, 2026, exploited preinstall scripts to deliver different payloads based on the operating system, as detailed by Tenable.

This malware downloaded reverse shells for Linux and Windows and a JXA agent called Apfell for macOS. Its mature design suggests it evolved from a previous malicious package, eslint-verify-plugin.

- Advertisement -

Furthermore, the ambar-src package exfiltrated stolen data to a Yandex Cloud domain to blend with legitimate traffic. Tenable warned that any system with the package should be considered fully compromised, as removal does not guarantee all malware is eliminated.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Oracle E-Business Flaw Actively Exploited

A critical flaw in Oracle Payments (CVE-2026-46817) is being actively exploited to take over...

Tommy Robinson’s son behind his ‘patriotic’ crypto token

British activist Tommy Robinson shilled his son's "Patriotic Bull" cryptocurrency token on X before...

AI Browser Extension Intercepted User Searches

A malicious Chrome extension impersonating the AI search engine Perplexity intercepted and logged user...

Saylor’s MicroStrategy to Sell Bitcoin Amid Crypto Slump

Strategy announced a new program authorizing the sale of up to $1.25 billion worth...

$3.7B in Stablecoins Frozen by Censorship

Tether and Circle have frozen approximately $3.7 billion in stablecoins on the Ethereum and...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading