Threat reportSupply ChainTL-2026-0473

Malicious NuGet Packages Impersonate Chinese UI Libraries — IR.* Infostealer With clrjit.dll JIT Hook, Reactor RSA-1024 Anti-Tamper, and Multi-Browser/Wallet/SSH Theft

criticalACTIVE

Malicious NuGet Packages Impersonate Chinese UI Libraries (TL-2026-0473), also tracked as IR.* NuGet Campaign, is a critical-severity supply-chain compromise, first published 2026-05-07. It has no confirmed attribution, affects NuGet (Microsoft) NuGet Package Registry, maps to 30 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
30MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-0473

Threat ID
TL-2026-0473
Also known as
IR.* NuGet Campaign, AntdUI Impersonation Campaign, bmrxntfj NuGet Compromise
Severity
CRITICAL
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, financial, cryptocurrency, gaming, government, manufacturing, telecommunications
Target regions
Asia, China, North America, Europe, Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in Malicious NuGet Packages Impersonate Chinese UI Libraries

Malware and tooling: Agent Racoon, ArrowRAT, Lumma Stealer - S1213, Quantum Stealer (Reactor-modulus pivot)

How Malicious NuGet Packages Impersonate Chinese UI Libraries works

Five NuGet packages (IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32) published by NuGet account 'bmrxntfj' impersonate Chinese .NET UI/infrastructure libraries — most notably AntdUI — accumulating ~65,000 downloads since late September 2025 across 224 versions (219 deliberately hidden). A .NET Reactor-protected module initializer verifies an RSA-1024 anti-tamper signature, allocates RWX memory, decrypts a stage-2 blob, and hooks clrjit.dll!getJit (with /proc/self/mem and libclrjit equivalents on Linux/macOS) so every JIT compilation passes attacker-controlled code. The decrypted stage-2 (we4ftg.exe, ~786 KB) harvests credentials from 12+ Chromium browsers — including Chrome v20 AppBound encryption via the IElevator COM interface — plus Firefox/Thunderbird, 13 cryptocurrency wallets, OpenSSH id_rsa, Outlook profiles, Steam, and selected Desktop/Documents/Downloads files, staging to C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltrating to https://dns-providersa2[.]com/upload (62.84.102.85, VDSINA Amsterdam, Njalla privacy registrar). Reactor-modulus pivoting links the campaign to Lumma, Quantum, AgentRacoon, and ArrowRAT samples, suggesting a shared operator or builder.

Socket Threat Research disclosed on 2026-05-06 that a NuGet account named 'bmrxntfj' had been publishing weaponized .NET libraries that impersonate the Chinese-language UI library AntdUI and adjacent infrastructure packages. Five packages are confirmed malicious: IR.DantUI (a near-homoglyph of AntdUI), IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32. Across these, the operator pushed 224 distinct versions, 219 of which were hidden (unlisted) immediately after publication — a deliberate evasion that lets the operator burn a version after a researcher pulls it while leaving installable copies for victims who pinned earlier numbers. Cumulative download telemetry is ~65,000 since late September 2025, with the campaign predominantly targeting developer workstations and build agents that consume Chinese-language .NET ecosystems.

The core technical innovation is a JIT hook delivered through a module initializer. When the malicious assembly is loaded, the Reactor-protected module initializer first verifies an RSA-1024 signature embedded alongside the payload — a builder-style anti-tamper check that prevents researchers from trivially patching the loader before letting it execute. After the signature check passes, the loader allocates a region of RWX memory via VirtualAlloc(NULL, size, MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE), decrypts a stage-2 blob into it, and resolves clrjit.dll!getJit. It overwrites the prologue of getJit so that every subsequent JIT compilation in the host process is intercepted; the hook can rewrite IL or native bytes for any compiled method, providing complete in-process code-substitution capability. The same primitive is implemented for Linux (writing to /proc/self/mem to overwrite the equivalent libclrjit symbol) and macOS (resolving libclrjit.dylib via dlsym and writing through mprotect/RWX), making the technique cross-platform across the .NET runtime.

The in-memory stage drops we4ftg.exe (~786 KB, .NET infostealer) and a helper s4.exe to %ProgramData%, plus two fake DLLs (CRYPT32.DLL.MUI and mscorrc.dll) used as side-loading or proxy targets. we4ftg.exe enumerates 12+ Chromium-based browsers and harvests Login Data, Cookies, Web Data, History, Bookmarks, and Local State; for Chrome 127+ it abuses the AppBound encryption mitigation by instantiating the IElevator COM interface to obtain the decrypted app-bound key, defeating the v20 protection. Firefox and Thunderbird profiles are dumped (key4.db / logins.json / cookies.sqlite), Outlook PST/OST and registry credentials are extracted, the Steam loginusers.vdf and ssfn token are pulled, and OpenSSH %USERPROFILE%\.ssh\id_rsa / id_ed25519 / known_hosts are exfiltrated wholesale. Thirteen cryptocurrency wallets are targeted, including Exodus, Electrum, Atomic, Coinomi, Jaxx, Wasabi, Guarda, Binance, MetaMask (browser extension wallet store), Trust, Phantom, Solflare, and Daedalus. The collection is staged into C:\ProgramData\Microsoft OneDrive\keys.dat (a single-pass archive) and uploaded to https://dns-providersa2[.]com/upload over HTTPS with randomized X-{abc} 3-letter-lowercase headers used as a covert build-tag channel; a /check beacon is used for liveness.

The C2 domain dns-providersa2.com was registered through Njalla (a privacy-forward registrar long associated with criminal infrastructure) on 2026-03-12 and resolved to 62.84.102.85 — a VDSINA VPS in Amsterdam (AS48666). A development/staging server git.justdotrip.com hosted on Alibaba Cloud was used to push code prior to packaging. Pivoting on the RSA-1024 modulus embedded in the Reactor protection scheme yields four additional VirusTotal artifacts that share the same key material with samples attributed to Lumma Stealer, Quantum Stealer, AgentRacoon (an Iran-nexus backdoor disclosed by PAN Unit 42), and ArrowRAT — strongly suggesting a shared builder or operator that supplies multiple infostealer/RAT brands. Attribution remains unset, but the pivot hints at a malware-as-a-service or shared cryptor backend rather than a one-off campaign.

Defenders should treat any host that consumed an IR.* package after September 2025 as compromised: rotate browser-stored credentials, OAuth tokens, SSH keys, wallet seeds, and CI/CD secrets; assume CI build agents that referenced these libraries leaked their pipeline tokens. Block the IOCs at egress, hunt for clrjit.dll prologue modifications and RWX allocations originating from .NET module initializers, and flag any presence of C:\ProgramData\Microsoft OneDrive\keys.dat as high-confidence compromise.

MITRE ATT&CK techniques used in TL-2026-0473

Collection

T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1195 Supply Chain Compromise

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Persistence

T1546 Event Triggered Execution

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

defense-impairment

T1601 Modify System Image

Impact

T1657 Financial Theft

Affected products and versions in Malicious NuGet Packages Impersonate Chinese UI Libraries

  • NuGet (Microsoft) — NuGet Package Registry
    Vulnerable versions: IR.DantUI (all versions, 2025-09-XX through 2026-05-06); IR.OscarUI (all versions, 2025-09-XX through 2026-05-06); IR.Infrastructure.Core (all versions); IR.Infrastructure.DataService.Core (all versions); IR.iplus32 (all versions)
    Fixed in: Packages removed by NuGet following Socket disclosure
  • Google — Chrome (impacted browser)
    Vulnerable versions: Chrome v20 AppBound-protected installations on hosts that ran an IR.* package
  • Mozilla — Firefox / Thunderbird
    Vulnerable versions: All profile-based versions on impacted hosts
  • .NET Foundation / Microsoft — .NET runtime (clrjit.dll target)
    Vulnerable versions: .NET Framework 4.x, .NET 6/7/8/9 with clrjit.dll, libclrjit.so, libclrjit.dylib

Remediation for Malicious NuGet Packages Impersonate Chinese UI Libraries

Patches

  • No vendor patch — this is a malicious-package campaign, not a software vulnerability. Remove the packages and remediate compromised hosts.

Immediate actions

  • Block dns-providersa2.com, git.justdotrip.com, and 62.84.102.85 at egress proxies, DNS, and EDR network rules
  • Inventory NuGet caches (%userprofile%\.nuget\packages, ~/.nuget/packages, build-agent caches) for IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32 — quarantine and remove
  • Search packages.lock.json, *.csproj, *.fsproj, paket.dependencies, Directory.Packages.props for any IR.* PackageReference; fail builds if found
  • On any host that consumed an IR.* package: revoke and rotate browser-stored web credentials, OAuth refresh tokens, password manager sessions, SSH private keys, GPG keys, crypto wallet seed phrases, Outlook account passwords, Steam tokens, and any CI/CD pipeline secrets present on the agent
  • Hunt for and remove C:\ProgramData\Microsoft OneDrive\keys.dat, %ProgramData%\we4ftg.exe, %ProgramData%\s4.exe, and the CRYPT32.DLL.MUI / mscorrc.dll fakes
  • Force password resets and MFA re-enrollment for any developer who installed an IR.* package since 2025-09-01
  • Treat any CI build agent that restored these dependencies as compromised: rotate SSH deploy keys, GitHub/GitLab PATs, registry credentials, cloud OIDC secrets, and code-signing certs

Workarounds

  • Pin to known-good NuGet sources only (nuget.org with signed-publisher requirement, internal mirror); disable arbitrary feeds
  • Configure nuget.config with packageSourceMapping so untrusted package IDs cannot be silently substituted
  • Run dotnet restore --locked-mode and require packages.lock.json review in code review
  • For sensitive build agents, run dotnet restore in an ephemeral container with no host access to credential files (.ssh, browser profiles, wallets)

Longer-term hardening

  • Enforce NuGet package signing requirements and signed-only feeds in nuget.config; reject unsigned third-party packages in CI
  • Mirror approved third-party NuGet packages through an internal proxy (Artifactory / Azure Artifacts upstream) with manual review for new publishers
  • Allowlist verified publishers for first-party-equivalent libraries (e.g., AntdUI's actual maintainer) and alert on new typosquats
  • Deploy SCA tooling (Socket, Snyk, Endor Labs) in pull-request gates to flag suspicious NuGet package metadata and behavior
  • Network-isolate CI build agents from the public internet and route package fetches only through reviewed mirrors
  • Add EDR detections for clrjit.dll prologue modification, RWX allocations from module initializers, and dotnet.exe/MSBuild.exe child processes spawning from .nuget restore directories

Weaknesses (CWE) in Malicious NuGet Packages Impersonate Chinese UI Libraries

CWE-506, CWE-829, CWE-494, CWE-1357

Timeline of Malicious NuGet Packages Impersonate Chinese UI Libraries

  • Earliest IR.* package version published to NuGet by account 'bmrxntfj'; campaign begins with low-volume seeding of impersonated AntdUI library.
  • Operator begins systematic version-rotation: hiding (unlisting) recent versions while pushing new builds, eventually reaching 224 versions across 5 packages with 219 hidden.
  • C2 domain dns-providersa2.com registered through Njalla privacy registrar; resolves to 62.84.102.85 on VDSINA VPS in Amsterdam (AS48666).
  • NuGet account 'bmrxntfj' last observed publishing/modifying IR.* packages prior to disclosure; cumulative downloads near ~65,000.
  • Telemetry shows active stage-2 (we4ftg.exe) execution and exfiltration to https://dns-providersa2.com/upload across multiple developer environments.
  • Socket Threat Research publishes full technical disclosure of the campaign — JIT hook, RSA-1024 anti-tamper, AppBound bypass, wallet/SSH theft, and Lumma/Quantum/AgentRacoon/ArrowRAT modulus pivot.
  • Threadlinqs Intelligence (AII-Researcher) publishes TL-2026-0473 with full IOC set, MITRE mapping, detections, and remediation guidance.
  • GBHackers and Cyber Press publish secondary coverage; NuGet begins removing the 5 IR.* packages and the bmrxntfj account.
  • As of 2026-05-29, the bmrxntfj IR.* NuGet infostealer campaign remains ACTIVE: all 5 malicious packages (IR.DantUI, IR.OscarUI, IR.iplus32, IR.Infrastructure.Core) are still live and installable on NuGet despite Socket's 2026-05-06 takedown request, and C2 dns-providersa2.com still resolves to 62.84.102.85. No arrest, sinkhole, or operator stand-down reported.

Sources cited for Malicious NuGet Packages Impersonate Chinese UI Libraries

Detection coverage for TL-2026-0473

As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0473 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats