BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious NuGet, npm Packages Target Developers

Sophisticated NuGet and npm attacks target developers, stealing data and planting backdoors in applications.

  • NuGet campaign exfiltrated ASP.NET Identity data and created backdoors after amassing over 4,500 downloads.
  • Separately, a malicious npm package, ambar-src, was downloaded over 50,000 times before its removal.
  • Both supply chain attacks target developers to compromise the applications they build or the machines they use.

Cybersecurity researchers uncovered a sophisticated attack in February 2026, where four malicious NuGet packages targeted ASP.NET developers through the repository. The packages, downloaded thousands of times, aimed to steal sensitive identity data and manipulate authorization rules within web applications.

- Advertisement -

Published in August 2024 by a user named hamzazaheer, the packages worked in concert to establish a C2 proxy and exfiltrate information. Security researcher Kush Pandya explained the objective was to compromise the applications developers build rather than their machines directly.

Consequently, attackers could gain persistent admin-level access to any deployed application instance. The campaign’s components included a dropper, credential stealers, and a utility for hidden file execution.

Meanwhile, a separate npm campaign was discovered involving the package ambar-src. This malicious code, uploaded on February 13, 2026, exploited preinstall scripts to deliver different payloads based on the operating system, as detailed by Tenable.

This malware downloaded reverse shells for Linux and Windows and a JXA agent called Apfell for macOS. Its mature design suggests it evolved from a previous malicious package, eslint-verify-plugin.

- Advertisement -

Furthermore, the ambar-src package exfiltrated stolen data to a Yandex Cloud domain to blend with legitimate traffic. Tenable warned that any system with the package should be considered fully compromised, as removal does not guarantee all malware is eliminated.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Australia payment rails may adapt for tokenized money

Australian regulators see tokenized money like stablecoins and deposit tokens as a design factor...

Linux “Copy Fail” Bug Lets Local Users Gain Root

A critical Linux flaw allows an unprivileged local user to write to a file's...

Strong Meta Q1 2026 Earnings Beat Can’t Prevent Stock Plunge

Meta's strong Q1 2026 earnings were overshadowed by a higher 2026 capex forecast, causing...

Trump-Linked WLFI Token Plunges 14% Amid Lockup Vote

The World Liberty Financial (WLFI) token dropped nearly 14% Wednesday amid a controversial governance...

Microsoft, Alphabet Surge on AI as OpenAI Stumbles

Google Cloud revenue surged 63% year-over-year to $20.03 billion in Q1 2026, with enterprise...

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading