BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious NuGet, npm Packages Target Developers

Sophisticated NuGet and npm attacks target developers, stealing data and planting backdoors in applications.

  • NuGet campaign exfiltrated ASP.NET Identity data and created backdoors after amassing over 4,500 downloads.
  • Separately, a malicious npm package, ambar-src, was downloaded over 50,000 times before its removal.
  • Both supply chain attacks target developers to compromise the applications they build or the machines they use.

Cybersecurity researchers uncovered a sophisticated attack in February 2026, where four malicious NuGet packages targeted ASP.NET developers through the repository. The packages, downloaded thousands of times, aimed to steal sensitive identity data and manipulate authorization rules within web applications.

- Advertisement -

Published in August 2024 by a user named hamzazaheer, the packages worked in concert to establish a C2 proxy and exfiltrate information. Security researcher Kush Pandya explained the objective was to compromise the applications developers build rather than their machines directly.

Consequently, attackers could gain persistent admin-level access to any deployed application instance. The campaign’s components included a dropper, credential stealers, and a utility for hidden file execution.

Meanwhile, a separate npm campaign was discovered involving the package ambar-src. This malicious code, uploaded on February 13, 2026, exploited preinstall scripts to deliver different payloads based on the operating system, as detailed by Tenable.

This malware downloaded reverse shells for Linux and Windows and a JXA agent called Apfell for macOS. Its mature design suggests it evolved from a previous malicious package, eslint-verify-plugin.

- Advertisement -

Furthermore, the ambar-src package exfiltrated stolen data to a Yandex Cloud domain to blend with legitimate traffic. Tenable warned that any system with the package should be considered fully compromised, as removal does not guarantee all malware is eliminated.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MemTensor npm, PyPI packages push credential-stealing malware

Compromised MemTensor packages on npm and PyPI delivered the Go-based sckit implant across Windows,...

Micron stock nears $1,100 as split speculation builds

Micron shares closed at $1,096.16, nearing $1,100, but the company has not announced a...

Bitcoin cools after rally; ZEC, HYPE hit new ATHs

Bitcoin pushed past $86,500 Tuesday with total crypto market cap above $3 trillion, while...

CME Bitcoin Cash Futures Planned, BCH Jumps 30%

CME Group plans to launch Bitcoin Cash futures and Micro Bitcoin Cash futures on...

Next.js Critical Flaw in ImageResponse Allows Server RCE

A critical vulnerability (CVE-2026-94545, CVSS 9.5) in Next.js versions 16.2.0 through 16.3.5 allows remote...

Must Read

What is Moon Tropica (CAH) – Technology, Tokenomics, Game Preview

Gaming enthusiasts and crypto enthusiasts, hHave you heard about Moon Tropica? If you're longing for that nostalgic feel of classic games from your childhood...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading