Threat reportSupply ChainTL-2026-0137

Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy C2

highRESOLVED

Malicious NuGet Packages (TL-2026-0137), also tracked as NCryptYo Campaign, is a high-severity supply-chain compromise, first published 2026-02-24. It has no confirmed attribution, affects Microsoft NuGet Package Manager, maps to 25 MITRE ATT&CK techniques (T1005, T1027, T1027.009), and is covered by 9 detection rules and 17 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0137

Threat ID
TL-2026-0137
Also known as
NCryptYo Campaign, NuGet JIT Hook Campaign
Severity
HIGH
Status
RESOLVED
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
technology, developer, enterprise, financial, government
Target regions
Global
Detection rules
9
Indicators of compromise
17

Malware and tooling in Malicious NuGet Packages

Malware and tooling: 06062730-b307-48a6-a7c3-140e6bae4587

How Malicious NuGet Packages works

Socket Security discovered 4 malicious NuGet packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) published by threat actor 'hamzazaheer' targeting ASP.NET developers. NCryptYo is a heavily obfuscated stage-1 dropper using JIT compiler hooks to decrypt embedded payloads and deploy a localhost proxy on port 7152. Companion packages exfiltrate ASP.NET Identity data (users, roles, permissions) and accept attacker-controlled authorization rules creating persistent backdoors in production applications. 4,500+ downloads. 1/72 AV detection rate.

Socket Security's Threat Research Team discovered a sophisticated NuGet supply chain attack involving four coordinated malicious packages targeting ASP.NET web application developers. The campaign deploys a multi-stage payload architecture where each package serves a distinct role in the kill chain.

NCryptYo is the stage-1 dropper that masquerades as the legitimate NCrypto cryptography library through a three-layer naming attack: the package name typosquats NCrypto, the DLL filename NCrypt.dll mimics Windows' CNG cryptography provider (C:\Windows\System32\NCrypt.dll), and the namespace NCrypt matches Microsoft's cryptography APIs. All public methods return null unconditionally — the real functionality is encrypted and only decrypted at runtime through JIT compiler manipulation.

The dropper uses a sophisticated execution-on-load technique: its static constructor fires immediately when the assembly loads (requiring only a 'using NCrypt;' statement). It installs JIT compiler hooks by hijacking the .NET runtime's compileMethod vtable entry using native OS functions (VirtualAlloc on Windows, mmap on Unix). Platform-specific shellcode is written: 39 bytes for x64, 29 bytes for x86, 32 bytes for ARM64 (targeting Apple Silicon). Every method carries [MethodImpl(MethodImplOptions.NoInlining)] to force all calls through the modified JIT where encrypted method bodies are decrypted and compiled.

The DLL is protected with Eziriz .NET Reactor obfuscator (unregistered version with 14-day time bomb), [SuppressIldasm] attributes, RSA signature verification for tamper detection, and a custom VM engine implementing IL virtualization — a second obfuscation layer where critical methods are converted to proprietary bytecode. Five encrypted resources are embedded, with the largest being a 126 KB DOS executable (stage-2 payload) encrypted with AES-256-CBC. A second AES key, obfuscated across 200 lines of arithmetic, decrypts an RSA key. Thirteen SHA256 hashes are stored in the .text section for VM engine operation.

Anti-analysis defenses include Debugger.IsAttached checks, RSA signature verification against SHA1 hash of PE sections, and the time bomb. The DLL exports an entry point at ordinal #1, enabling standalone execution via rundll32.exe NCrypt.dll,#1 — providing distribution beyond NuGet. VirusTotal shows only 1/72 detection rate.

The stage-2 payload (126 KB) establishes a localhost proxy on port 7152 that relays traffic to the attacker's external C2 server. The C2 address is dynamically retrieved at runtime, never appearing in static artifacts. NCryptYo itself contains zero networking code — all System.Net.* types are absent from metadata.

DOMOAuth2_ integrates into ASP.NET applications via dependency injection (AddOAuth extension method) and exfiltrates ASP.NET Identity data through four API endpoints: get-permissions (AspUserId, AspRoleId), get-role-permissions (RoleId, RoleName), update-role-permissions (RoleId, ModuleIds), update-user-permissions (UserId, AspNetUserId, UserRoles). Every request includes a hardcoded auth token. The C2 response through the Message.Data field (typed dynamic) enables injection of modified authorization rules — creating a persistent backdoor where the attacker can grant admin roles, modify access controls, or disable security checks.

IRAOAuth2.0 implements the same four endpoints but removes all configurability — the hardcoded auth token is inlined and caller-supplied keys are completely ignored. This creates a redundant exfiltration channel that operates even if DOMOAuth2_ is discovered and disabled.

SimpleWriter_ presents as a PDF conversion utility but unconditionally writes attacker-controlled content to disk and executes local binaries with CreateNoWindow=true. Every ConvertHtmlToPDF() call beacons to the C2, writes files, and spawns hidden processes. The wkhtmltopdf.exe binary isn't shipped — it's placed by the NCryptYo stage-1 dropper.

All three companion packages share a byte-identical authentication token encoded with GZip compression and custom Base64 substitutions (_@_ for +, _~_ for /, _@@_ for =). The decoded token reveals a hardcoded API key and ProjectId (06062730-b307-48a6-a7c3-140e6bae4587). Assembly metadata shows identical build environments (Windows NT 10.0.22631, NuGet Pack 6.10.0.97, LangVersion 12.0). PDB paths expose source locations: E:\Projects\A-Mark\Authorization\OAuth2.0\ and E:\Projects\ArhamSoft-Projects\ideal-broccoli\SimpleWriter\. Published between August 12-21, 2024 by 'hamzazaheer'.

The campaign's objective is not to compromise developer machines directly but to compromise the applications they build. The authorization backdoor persists into production deployments, enabling the attacker to grant admin access to any deployed instance.

MITRE ATT&CK techniques used in TL-2026-0137

collection

T1005 Data from Local System; T1213 Data from Information Repositories

defense-evasion

T1027 Obfuscated Files or Information; T1027.009 Embedded Payloads; T1036.005 Match Legitimate Resource Name or Location; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1480 Execution Guardrails; T1497.001 System Checks

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059.001 PowerShell; T1106 Native API; T1204.002 Malicious File

discovery

T1069.002 Domain Groups; T1087.002 Domain Account

command-and-control

T1071.001 Web Protocols; T1090.001 Internal Proxy; T1572 Protocol Tunneling

initial-access

T1195.002 Compromise Software Supply Chain; T1199 Trusted Relationship

credential-access

T1528 Steal Application Access Token; T1555 Credentials from Password Stores

privilege-escalation

T1546.015 Component Object Model Hijacking

stealth

T1574.001 DLL

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Malicious NuGet Packages

  • Microsoft — NuGet Package Manager
    Vulnerable versions: All versions consuming unverified packages
    Fixed in: Protected by package signature verification
  • Microsoft — ASP.NET Identity
    Vulnerable versions: All versions when malicious packages are installed
    Fixed in: Remove malicious packages and audit Identity data
  • Microsoft — .NET Runtime
    Vulnerable versions: netstandard2.1, net8.0 (JIT hook targets)
    Fixed in: No runtime patch — remove malicious packages

Remediation for Malicious NuGet Packages

Immediate actions

  • Remove NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ from all projects
  • Scan for localhost:7152 connections in network logs — indicates active C2 proxy
  • Check for NCrypt.dll in project output directories — compare SHA256 against IOCs
  • Audit ASP.NET Identity data for unauthorized role/permission modifications
  • Rotate all credentials stored in ASP.NET Identity if compromise suspected
  • Kill any process listening on port 7152 and investigate its origin

Workarounds

  • Verify package names carefully — NCryptYo typosquats legitimate NCrypto
  • Inspect static constructors in .NET packages — execution-on-load is a red flag
  • Decompile suspicious packages and check for .NET Reactor obfuscation markers
  • Block localhost:7152 at application firewall level if not used legitimately

Longer-term hardening

  • Implement NuGet package signature verification — require signed packages from trusted publishers
  • Enable packages.lock.json to pin dependency versions and detect unexpected changes
  • Add CI/CD security scanning that analyzes package contents before production builds
  • Monitor for JIT compiler manipulation indicators (getJit, compileMethod, VirtualProtect hooks)
  • Deploy network monitoring for persistent localhost connections to non-standard ports
  • Use Socket Security or similar tools to detect typosquatting and obfuscation in dependencies

Weaknesses (CWE) in Malicious NuGet Packages

CWE-494, CWE-829, CWE-506

Timeline of Malicious NuGet Packages

  • First malicious NuGet package published by threat actor 'hamzazaheer'. Campaign begins with coordinated uploads over 9-day window.
  • Packages begin accumulating downloads. NCryptYo typosquats legitimate NCrypto (5.7K downloads since 2013). Campaign reaches 4,500+ total downloads.
  • Last of 4 malicious packages published. All packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) now live on NuGet.org.
  • VirusTotal analysis shows only 1/72 security vendors detect NCrypt.dll. Sandbox confirms rundll32.exe execution path via ordinal #1 export.
  • Socket Security submits takedown requests to NuGet security team for all 4 packages.
  • Socket Security Threat Research Team discovers and publishes analysis of all 4 malicious packages. Source: https://socket.dev/blog/four-malicious-nuget-packages-target-asp-net-developers-with-jit-hooking-and-credential
  • Threadlinqs Intelligence Platform publishes TL-2026-0137 with full MITRE mapping, detections, and simulations.
  • As of 2026-05-29, all 4 malicious NuGet packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) were removed from NuGet.org after Socket's Feb 2026 disclosure, and actor 'hamzazaheer' now shows 0 packages/0 downloads. No CVE applies, no successor campaign is attributed to this actor, and distribution is dead—only residual backdoors in already-infected apps persist.

Sources cited for Malicious NuGet Packages

Detection coverage for TL-2026-0137

As of 2026-02-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0137 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats