Threat reportSupply ChainTL-2026-0473
Malicious NuGet Packages Impersonate Chinese UI Libraries — IR.* Infostealer With clrjit.dll JIT Hook, Reactor RSA-1024 Anti-Tamper, and Multi-Browser/Wallet/SSH Theft
Malicious NuGet Packages Impersonate Chinese UI Libraries (TL-2026-0473), also tracked as IR.* NuGet Campaign, is a critical-severity supply-chain compromise, first published 2026-05-07. It has no confirmed attribution, affects NuGet (Microsoft) NuGet Package Registry, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 27 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 30MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-0473
- Threat ID
- TL-2026-0473
- Also known as
- IR.* NuGet Campaign, AntdUI Impersonation Campaign, bmrxntfj NuGet Compromise
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, financial, cryptocurrency, gaming, government, manufacturing, telecommunications
- Target regions
- Asia, China, North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Malicious NuGet Packages Impersonate Chinese UI Libraries
Malware and tooling: Agent Racoon, ArrowRAT, Lumma Stealer - S1213, Quantum Stealer (Reactor-modulus pivot)
How Malicious NuGet Packages Impersonate Chinese UI Libraries works
Five NuGet packages (IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32) published by NuGet account 'bmrxntfj' impersonate Chinese .NET UI/infrastructure libraries — most notably AntdUI — accumulating ~65,000 downloads since late September 2025 across 224 versions (219 deliberately hidden). A .NET Reactor-protected module initializer verifies an RSA-1024 anti-tamper signature, allocates RWX memory, decrypts a stage-2 blob, and hooks clrjit.dll!getJit (with /proc/self/mem and libclrjit equivalents on Linux/macOS) so every JIT compilation passes attacker-controlled code. The decrypted stage-2 (we4ftg.exe, ~786 KB) harvests credentials from 12+ Chromium browsers — including Chrome v20 AppBound encryption via the IElevator COM interface — plus Firefox/Thunderbird, 13 cryptocurrency wallets, OpenSSH id_rsa, Outlook profiles, Steam, and selected Desktop/Documents/Downloads files, staging to C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltrating to https://dns-providersa2[.]com/upload (62.84.102.85, VDSINA Amsterdam, Njalla privacy registrar). Reactor-modulus pivoting links the campaign to Lumma, Quantum, AgentRacoon, and ArrowRAT samples, suggesting a shared operator or builder.
Socket Threat Research disclosed on 2026-05-06 that a NuGet account named 'bmrxntfj' had been publishing weaponized .NET libraries that impersonate the Chinese-language UI library AntdUI and adjacent infrastructure packages. Five packages are confirmed malicious: IR.DantUI (a near-homoglyph of AntdUI), IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32. Across these, the operator pushed 224 distinct versions, 219 of which were hidden (unlisted) immediately after publication — a deliberate evasion that lets the operator burn a version after a researcher pulls it while leaving installable copies for victims who pinned earlier numbers. Cumulative download telemetry is ~65,000 since late September 2025, with the campaign predominantly targeting developer workstations and build agents that consume Chinese-language .NET ecosystems.
The core technical innovation is a JIT hook delivered through a module initializer. When the malicious assembly is loaded, the Reactor-protected module initializer first verifies an RSA-1024 signature embedded alongside the payload — a builder-style anti-tamper check that prevents researchers from trivially patching the loader before letting it execute. After the signature check passes, the loader allocates a region of RWX memory via VirtualAlloc(NULL, size, MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE), decrypts a stage-2 blob into it, and resolves clrjit.dll!getJit. It overwrites the prologue of getJit so that every subsequent JIT compilation in the host process is intercepted; the hook can rewrite IL or native bytes for any compiled method, providing complete in-process code-substitution capability. The same primitive is implemented for Linux (writing to /proc/self/mem to overwrite the equivalent libclrjit symbol) and macOS (resolving libclrjit.dylib via dlsym and writing through mprotect/RWX), making the technique cross-platform across the .NET runtime.
The in-memory stage drops we4ftg.exe (~786 KB, .NET infostealer) and a helper s4.exe to %ProgramData%, plus two fake DLLs (CRYPT32.DLL.MUI and mscorrc.dll) used as side-loading or proxy targets. we4ftg.exe enumerates 12+ Chromium-based browsers and harvests Login Data, Cookies, Web Data, History, Bookmarks, and Local State; for Chrome 127+ it abuses the AppBound encryption mitigation by instantiating the IElevator COM interface to obtain the decrypted app-bound key, defeating the v20 protection. Firefox and Thunderbird profiles are dumped (key4.db / logins.json / cookies.sqlite), Outlook PST/OST and registry credentials are extracted, the Steam loginusers.vdf and ssfn token are pulled, and OpenSSH %USERPROFILE%\.ssh\id_rsa / id_ed25519 / known_hosts are exfiltrated wholesale. Thirteen cryptocurrency wallets are targeted, including Exodus, Electrum, Atomic, Coinomi, Jaxx, Wasabi, Guarda, Binance, MetaMask (browser extension wallet store), Trust, Phantom, Solflare, and Daedalus. The collection is staged into C:\ProgramData\Microsoft OneDrive\keys.dat (a single-pass archive) and uploaded to https://dns-providersa2[.]com/upload over HTTPS with randomized X-{abc} 3-letter-lowercase headers used as a covert build-tag channel; a /check beacon is used for liveness.
The C2 domain dns-providersa2.com was registered through Njalla (a privacy-forward registrar long associated with criminal infrastructure) on 2026-03-12 and resolved to 62.84.102.85 — a VDSINA VPS in Amsterdam (AS48666). A development/staging server git.justdotrip.com hosted on Alibaba Cloud was used to push code prior to packaging. Pivoting on the RSA-1024 modulus embedded in the Reactor protection scheme yields four additional VirusTotal artifacts that share the same key material with samples attributed to Lumma Stealer, Quantum Stealer, AgentRacoon (an Iran-nexus backdoor disclosed by PAN Unit 42), and ArrowRAT — strongly suggesting a shared builder or operator that supplies multiple infostealer/RAT brands. Attribution remains unset, but the pivot hints at a malware-as-a-service or shared cryptor backend rather than a one-off campaign.
Defenders should treat any host that consumed an IR.* package after September 2025 as compromised: rotate browser-stored credentials, OAuth tokens, SSH keys, wallet seeds, and CI/CD secrets; assume CI build agents that referenced these libraries leaked their pipeline tokens. Block the IOCs at egress, hunt for clrjit.dll prologue modifications and RWX allocations originating from .NET module initializers, and flag any presence of C:\ProgramData\Microsoft OneDrive\keys.dat as high-confidence compromise.
MITRE ATT&CK techniques used in TL-2026-0473
Collection
T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Persistence
T1546 Event Triggered Execution
stealth
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
defense-impairment
Impact
Affected products and versions in Malicious NuGet Packages Impersonate Chinese UI Libraries
- NuGet (Microsoft) — NuGet Package Registry
Vulnerable versions: IR.DantUI (all versions, 2025-09-XX through 2026-05-06); IR.OscarUI (all versions, 2025-09-XX through 2026-05-06); IR.Infrastructure.Core (all versions); IR.Infrastructure.DataService.Core (all versions); IR.iplus32 (all versions)
Fixed in: Packages removed by NuGet following Socket disclosure - Google — Chrome (impacted browser)
Vulnerable versions: Chrome v20 AppBound-protected installations on hosts that ran an IR.* package - Mozilla — Firefox / Thunderbird
Vulnerable versions: All profile-based versions on impacted hosts - .NET Foundation / Microsoft — .NET runtime (clrjit.dll target)
Vulnerable versions: .NET Framework 4.x, .NET 6/7/8/9 with clrjit.dll, libclrjit.so, libclrjit.dylib
Remediation for Malicious NuGet Packages Impersonate Chinese UI Libraries
Patches
- No vendor patch — this is a malicious-package campaign, not a software vulnerability. Remove the packages and remediate compromised hosts.
Immediate actions
- Block dns-providersa2.com, git.justdotrip.com, and 62.84.102.85 at egress proxies, DNS, and EDR network rules
- Inventory NuGet caches (%userprofile%\.nuget\packages, ~/.nuget/packages, build-agent caches) for IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32 — quarantine and remove
- Search packages.lock.json, *.csproj, *.fsproj, paket.dependencies, Directory.Packages.props for any IR.* PackageReference; fail builds if found
- On any host that consumed an IR.* package: revoke and rotate browser-stored web credentials, OAuth refresh tokens, password manager sessions, SSH private keys, GPG keys, crypto wallet seed phrases, Outlook account passwords, Steam tokens, and any CI/CD pipeline secrets present on the agent
- Hunt for and remove C:\ProgramData\Microsoft OneDrive\keys.dat, %ProgramData%\we4ftg.exe, %ProgramData%\s4.exe, and the CRYPT32.DLL.MUI / mscorrc.dll fakes
- Force password resets and MFA re-enrollment for any developer who installed an IR.* package since 2025-09-01
- Treat any CI build agent that restored these dependencies as compromised: rotate SSH deploy keys, GitHub/GitLab PATs, registry credentials, cloud OIDC secrets, and code-signing certs
Workarounds
- Pin to known-good NuGet sources only (nuget.org with signed-publisher requirement, internal mirror); disable arbitrary feeds
- Configure nuget.config with packageSourceMapping so untrusted package IDs cannot be silently substituted
- Run dotnet restore --locked-mode and require packages.lock.json review in code review
- For sensitive build agents, run dotnet restore in an ephemeral container with no host access to credential files (.ssh, browser profiles, wallets)
Longer-term hardening
- Enforce NuGet package signing requirements and signed-only feeds in nuget.config; reject unsigned third-party packages in CI
- Mirror approved third-party NuGet packages through an internal proxy (Artifactory / Azure Artifacts upstream) with manual review for new publishers
- Allowlist verified publishers for first-party-equivalent libraries (e.g., AntdUI's actual maintainer) and alert on new typosquats
- Deploy SCA tooling (Socket, Snyk, Endor Labs) in pull-request gates to flag suspicious NuGet package metadata and behavior
- Network-isolate CI build agents from the public internet and route package fetches only through reviewed mirrors
- Add EDR detections for clrjit.dll prologue modification, RWX allocations from module initializers, and dotnet.exe/MSBuild.exe child processes spawning from .nuget restore directories
Weaknesses (CWE) in Malicious NuGet Packages Impersonate Chinese UI Libraries
Timeline of Malicious NuGet Packages Impersonate Chinese UI Libraries
- Earliest IR.* package version published to NuGet by account 'bmrxntfj'; campaign begins with low-volume seeding of impersonated AntdUI library.
- Operator begins systematic version-rotation: hiding (unlisting) recent versions while pushing new builds, eventually reaching 224 versions across 5 packages with 219 hidden.
- C2 domain dns-providersa2.com registered through Njalla privacy registrar; resolves to 62.84.102.85 on VDSINA VPS in Amsterdam (AS48666).
- NuGet account 'bmrxntfj' last observed publishing/modifying IR.* packages prior to disclosure; cumulative downloads near ~65,000.
- Telemetry shows active stage-2 (we4ftg.exe) execution and exfiltration to https://dns-providersa2.com/upload across multiple developer environments.
- Socket Threat Research publishes full technical disclosure of the campaign — JIT hook, RSA-1024 anti-tamper, AppBound bypass, wallet/SSH theft, and Lumma/Quantum/AgentRacoon/ArrowRAT modulus pivot.
- Threadlinqs Intelligence (AII-Researcher) publishes TL-2026-0473 with full IOC set, MITRE mapping, detections, and remediation guidance.
- GBHackers and Cyber Press publish secondary coverage; NuGet begins removing the 5 IR.* packages and the bmrxntfj account.
- As of 2026-05-29, the bmrxntfj IR.* NuGet infostealer campaign remains ACTIVE: all 5 malicious packages (IR.DantUI, IR.OscarUI, IR.iplus32, IR.Infrastructure.Core) are still live and installable on NuGet despite Socket's 2026-05-06 takedown request, and C2 dns-providersa2.com still resolves to 62.84.102.85. No arrest, sinkhole, or operator stand-down reported.
Sources cited for Malicious NuGet Packages Impersonate Chinese UI Libraries
- Socket — 5 Malicious NuGet Packages Impersonate Chinese UI Libraries
- GBHackers — Malicious NuGet Packages Steal Browser Credentials, SSH Keys, and Crypto Wallets
- Cyber Press — Cybercriminals Use NuGet Packages To Harvest Developer Secrets
- NuGet — bmrxntfj profile (5 IR.* packages)
- MITRE ATT&CK — T1195.002 Compromise Software Supply Chain
- Google Chromium — App-Bound Encryption (v20) design notes
- Palo Alto Unit 42 — AgentRacoon Backdoor (Reactor-modulus pivot family)
- .NET Reactor — Module initializer and anti-tamper documentation
Detection coverage for TL-2026-0473
As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0473 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.