# Malicious NuGet Packages Impersonate Chinese UI Libraries — IR.* Infostealer With clrjit.dll JIT Hook, Reactor RSA-1024 Anti-Tamper, and Multi-Browser/Wallet/SSH Theft

> Five NuGet packages (IR.DantUI, IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, IR.iplus32) published by NuGet account 'bmrxntfj' impersonate Chinese .NET UI/infrastructure libraries — most notably AntdUI — accumulating ~65,000 downloads since late September 2025 across 224 versions (219 deliberately hidden). A .NET Reactor-protected module initializer verifies an RSA-1024 anti-tamper signature, allocates RWX memory, decrypts a stage-2 blob, and hooks clrjit.dll!getJit (with /proc/self/mem and libclrjit equivalents on Linux/macOS) so every JIT compilation passes attacker-controlled code. The decrypted stage-2 (we4ftg.exe, ~786 KB) harvests credentials from 12+ Chromium browsers — including Chrome v20 AppBound encryption via the IElevator COM interface — plus Firefox/Thunderbird, 13 cryptocurrency wallets, OpenSSH id_rsa, Outlook profiles, Steam, and selected Desktop/Documents/Downloads files, staging to C:\ProgramData\Microsoft OneDrive\keys.dat before exfiltrating to https://dns-providersa2[.]com/upload (62.84.102.85, VDSINA Amsterdam, Njalla privacy registrar). Reactor-modulus pivoting links the campaign to Lumma, Quantum, AgentRacoon, and ArrowRAT samples, suggesting a shared operator or builder.

- **Published:** 2026-05-07T12:00:00Z
- **Last reviewed:** 2026-05-07T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0473
- **ID:** TL-2026-0473
- **Severity:** CRITICAL
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Socket Threat Research disclosed on 2026-05-06 that a NuGet account named 'bmrxntfj' had been publishing weaponized .NET libraries that impersonate the Chinese-language UI library AntdUI and adjacent infrastructure packages. Five packages are confirmed malicious: IR.DantUI (a near-homoglyph of AntdUI), IR.OscarUI, IR.Infrastructure.Core, IR.Infrastructure.DataService.Core, and IR.iplus32. Across these, the operator pushed 224 distinct versions, 219 of which were hidden (unlisted) immediately after publication — a deliberate evasion that lets the operator burn a version after a researcher pulls it while leaving installable copies for victims who pinned earlier numbers. Cumulative download telemetry is ~65,000 since late September 2025, with the campaign predominantly targeting developer workstations and build agents that consume Chinese-language .NET ecosystems.

The core technical innovation is a JIT hook delivered through a module initializer. When the malicious assembly is loaded, the Reactor-protected module initializer first verifies an RSA-1024 signature embedded alongside the payload — a builder-style anti-tamper check that prevents researchers from trivially patching the loader before letting it execute. After the signature check passes, the loader allocates a region of RWX memory via VirtualAlloc(NULL, size, MEM_COMMIT|MEM_RESERVE, PAGE_EXECUTE_READWRITE), decrypts a stage-2 blob into it, and resolves clrjit.dll!getJit. It overwrites the prologue of getJit so that every subsequent JIT compilation in the host process is intercepted; the hook can rewrite IL or native bytes for any compiled method, providing complete in-process code-substitution capability. The same primitive is implemented for Linux (writing to /proc/self/mem to overwrite the equivalent libclrjit symbol) and macOS (resolving libclrjit.dylib via dlsym and writing through mprotect/RWX), making the technique cross-platform across the .NET runtime.

The in-memory stage drops we4ftg.exe (~786 KB, .NET infostealer) and a helper s4.exe to %ProgramData%, plus two fake DLLs (CRYPT32.DLL.MUI and mscorrc.dll) used as side-loading or proxy targets. we4ftg.exe enumerates 12+ Chromium-based browsers and harvests Login Data, Cookies, Web Data, History, Bookmarks, and Local State; for Chrome 127+ it abuses the AppBound encryption mitigation by instantiating the IElevator COM interface to obtain the decrypted app-bound key, defeating the v20 protection. Firefox and Thunderbird profiles are dumped (key4.db / logins.json / cookies.sqlite), Outlook PST/OST and registry credentials are extracted, the Steam loginusers.vdf and ssfn token are pulled, and OpenSSH %USERPROFILE%\.ssh\id_rsa / id_ed25519 / known_hosts are exfiltrated wholesale. Thirteen cryptocurrency wallets are targeted, including Exodus, Electrum, Atomic, Coinomi, Jaxx, Wasabi, Guarda, Binance, MetaMask (browser extension wallet store), Trust, Phantom, Solflare, and Daedalus. The collection is staged into C:\ProgramData\Microsoft OneDrive\keys.dat (a single-pass archive) and uploaded to https://dns-providersa2[.]com/upload over HTTPS with randomized X-{abc} 3-letter-lowercase headers used as a covert build-tag channel; a /check beacon is used for liveness.

The C2 domain dns-providersa2.com was registered through Njalla (a privacy-forward registrar long associated with criminal infrastructure) on 2026-03-12 and resolved to 62.84.102.85 — a VDSINA VPS in Amsterdam (AS48666). A development/staging server git.justdotrip.com hosted on Alibaba Cloud was used to push code prior to packaging. Pivoting on the RSA-1024 modulus embedded in the Reactor protection scheme yields four additional VirusTotal artifacts that share the same key material with samples attributed to Lumma Stealer, Quantum Stealer, AgentRacoon (an Iran-nexus backdoor disclosed by PAN Unit 42), and ArrowRAT — strongly suggesting a shared builder or operator that supplies multiple infostealer/RAT brands. Attribution remains unset, but the pivot hints at a malware-as-a-service or shared cryptor backend rather than a one-off campaign.

Defenders should treat any host that consumed an IR.* package after September 2025 as compromised: rotate browser-stored credentials, OAuth tokens, SSH keys, wallet seeds, and CI/CD secrets; assume CI build agents that referenced these libraries leaked their pipeline tokens. Block the IOCs at egress, hunt for clrjit.dll prologue modifications and RWX allocations originating from .NET module initializers, and flag any presence of C:\ProgramData\Microsoft OneDrive\keys.dat as high-confidence compromise.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1129 Shared Modules
- T1546 Event Triggered Execution
- T1574 Hijack Execution Flow
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1055 Process Injection
- T1036 Masquerading
- T1601 Modify System Image
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1539 Steal Web Session Cookie
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1560 Archive Collected Data
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [Socket — 5 Malicious NuGet Packages Impersonate Chinese UI Libraries](https://socket.dev/blog/5-malicious-nuget-packages-impersonate-chinese-ui-libraries)
- [GBHackers — Malicious NuGet Packages Steal Browser Credentials, SSH Keys, and Crypto Wallets](https://gbhackers.com/malicious-nuget-packages-2/)
- [Cyber Press — Cybercriminals Use NuGet Packages To Harvest Developer Secrets](https://cyberpress.org/nuget-malware-steals-secrets/)
- [NuGet — bmrxntfj profile (5 IR.* packages)](https://www.nuget.org/profiles/bmrxntfj)
- [MITRE ATT&CK — T1195.002 Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [Google Chromium — App-Bound Encryption (v20) design notes](https://chromium.googlesource.com/chromium/src/+/refs/heads/main/docs/security/app-bound-encryption.md)
- [Palo Alto Unit 42 — AgentRacoon Backdoor (Reactor-modulus pivot family)](https://unit42.paloaltonetworks.com/iran-affiliated-threat-actor-targets-aerospace-defense/)
- [.NET Reactor — Module initializer and anti-tamper documentation](https://www.eziriz.com/dotnet_reactor.htm)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0473
