# Malicious NuGet Packages — JIT Hooking ASP.NET Identity Exfiltration and Persistent Backdoor via Local Proxy C2

> Socket Security discovered 4 malicious NuGet packages (NCryptYo, DOMOAuth2_, IRAOAuth2.0, SimpleWriter_) published by threat actor 'hamzazaheer' targeting ASP.NET developers. NCryptYo is a heavily obfuscated stage-1 dropper using JIT compiler hooks to decrypt embedded payloads and deploy a localhost proxy on port 7152. Companion packages exfiltrate ASP.NET Identity data (users, roles, permissions) and accept attacker-controlled authorization rules creating persistent backdoors in production applications. 4,500+ downloads. 1/72 AV detection rate.

- **Published:** 2026-02-24T16:45:00Z
- **Last reviewed:** 2026-02-24T16:45:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0137
- **ID:** TL-2026-0137
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** RESOLVED
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket Security's Threat Research Team discovered a sophisticated NuGet supply chain attack involving four coordinated malicious packages targeting ASP.NET web application developers. The campaign deploys a multi-stage payload architecture where each package serves a distinct role in the kill chain.

NCryptYo is the stage-1 dropper that masquerades as the legitimate NCrypto cryptography library through a three-layer naming attack: the package name typosquats NCrypto, the DLL filename NCrypt.dll mimics Windows' CNG cryptography provider (C:\Windows\System32\NCrypt.dll), and the namespace NCrypt matches Microsoft's cryptography APIs. All public methods return null unconditionally — the real functionality is encrypted and only decrypted at runtime through JIT compiler manipulation.

The dropper uses a sophisticated execution-on-load technique: its static constructor fires immediately when the assembly loads (requiring only a 'using NCrypt;' statement). It installs JIT compiler hooks by hijacking the .NET runtime's compileMethod vtable entry using native OS functions (VirtualAlloc on Windows, mmap on Unix). Platform-specific shellcode is written: 39 bytes for x64, 29 bytes for x86, 32 bytes for ARM64 (targeting Apple Silicon). Every method carries [MethodImpl(MethodImplOptions.NoInlining)] to force all calls through the modified JIT where encrypted method bodies are decrypted and compiled.

The DLL is protected with Eziriz .NET Reactor obfuscator (unregistered version with 14-day time bomb), [SuppressIldasm] attributes, RSA signature verification for tamper detection, and a custom VM engine implementing IL virtualization — a second obfuscation layer where critical methods are converted to proprietary bytecode. Five encrypted resources are embedded, with the largest being a 126 KB DOS executable (stage-2 payload) encrypted with AES-256-CBC. A second AES key, obfuscated across 200 lines of arithmetic, decrypts an RSA key. Thirteen SHA256 hashes are stored in the .text section for VM engine operation.

Anti-analysis defenses include Debugger.IsAttached checks, RSA signature verification against SHA1 hash of PE sections, and the time bomb. The DLL exports an entry point at ordinal #1, enabling standalone execution via rundll32.exe NCrypt.dll,#1 — providing distribution beyond NuGet. VirusTotal shows only 1/72 detection rate.

The stage-2 payload (126 KB) establishes a localhost proxy on port 7152 that relays traffic to the attacker's external C2 server. The C2 address is dynamically retrieved at runtime, never appearing in static artifacts. NCryptYo itself contains zero networking code — all System.Net.* types are absent from metadata.

DOMOAuth2_ integrates into ASP.NET applications via dependency injection (AddOAuth extension method) and exfiltrates ASP.NET Identity data through four API endpoints: get-permissions (AspUserId, AspRoleId), get-role-permissions (RoleId, RoleName), update-role-permissions (RoleId, ModuleIds), update-user-permissions (UserId, AspNetUserId, UserRoles). Every request includes a hardcoded auth token. The C2 response through the Message.Data field (typed dynamic) enables injection of modified authorization rules — creating a persistent backdoor where the attacker can grant admin roles, modify access controls, or disable security checks.

IRAOAuth2.0 implements the same four endpoints but removes all configurability — the hardcoded auth token is inlined and caller-supplied keys are completely ignored. This creates a redundant exfiltration channel that operates even if DOMOAuth2_ is discovered and disabled.

SimpleWriter_ presents as a PDF conversion utility but unconditionally writes attacker-controlled content to disk and executes local binaries with CreateNoWindow=true. Every ConvertHtmlToPDF() call beacons to the C2, writes files, and spawns hidden processes. The wkhtmltopdf.exe binary isn't shipped — it's placed by the NCryptYo stage-1 dropper.

All three companion packages share a byte-identical authentication token encoded with GZip compression and custom Base64 substitutions (_@_ for +, _~_ for /, _@@_ for =). The decoded token reveals a hardcoded API key and ProjectId (06062730-b307-48a6-a7c3-140e6bae4587). Assembly metadata shows identical build environments (Windows NT 10.0.22631, NuGet Pack 6.10.0.97, LangVersion 12.0). PDB paths expose source locations: E:\Projects\A-Mark\Authorization\OAuth2.0\ and E:\Projects\ArhamSoft-Projects\ideal-broccoli\SimpleWriter\. Published between August 12-21, 2024 by 'hamzazaheer'.

The campaign's objective is not to compromise developer machines directly but to compromise the applications they build. The authorization backdoor persists into production deployments, enabling the attacker to grant admin access to any deployed instance.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1199 Trusted Relationship
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1106 Native API
- T1574.001 DLL
- T1546.015 Component Object Model Hijacking
- T1027 Obfuscated Files or Information
- T1027.009 Embedded Payloads
- T1140 Deobfuscate/Decode Files or Information
- T1036.005 Match Legitimate Resource Name or Location
- T1685 Disable or Modify Tools
- T1497.001 System Checks
- T1055 Process Injection
- T1480 Execution Guardrails
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1087.002 Domain Account
- T1069.002 Domain Groups
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1071.001 Web Protocols
- T1572 Protocol Tunneling
- T1090.001 Internal Proxy
- T1041 Exfiltration Over C2 Channel

## Sources

- [Socket Security: Four Malicious NuGet Packages Target ASP.NET Developers With JIT Hooking and Credential Exfiltration](https://socket.dev/blog/four-malicious-nuget-packages-target-asp-net-developers-with-jit-hooking-and-credential)
- [Socket Security — NCryptYo package analysis](https://socket.dev/nuget/package/ncryptyo/overview/1.0.1)
- [Socket Security — DOMOAuth2_ package analysis](https://socket.dev/nuget/package/domoauth2_/overview/1.0.20)
- [Socket Security — IRAOAuth2.0 package analysis](https://socket.dev/nuget/package/iraoauth2.0/overview/1.0.0)
- [Socket Security — SimpleWriter_ package analysis](https://socket.dev/nuget/package/simplewriter_/overview/1.0.5)
- [NuGet.org — hamzazaheer profile (threat actor)](https://www.nuget.org/profiles/hamzazaheer)
- [Legitimate NCrypto package (typosquatting target)](https://socket.dev/nuget/package/ncrypto)
- [MITRE ATT&CK — Supply Chain Compromise T1195.002](https://attack.mitre.org/techniques/T1195/002/)
- [Eziriz .NET Reactor — Obfuscation tool used by NCryptYo](https://www.eziriz.com/dotnet_reactor.htm)
- [Socket MCP — AI coding assistant package validation](https://socket.dev/blog/socket-mcp)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0137
