Skip to content
Supply Chain Attack Targets ASP.NET Developers via Malicious NuGet Packages

Supply Chain Attack Targets ASP.NET Developers via Malicious NuGet Packages

First seen 24 Feb 2026, 18:11 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

A supply chain attack has been identified, targeting ASP.NET developers through four malicious NuGet packages. The packages, named NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_, were published by a threat actor known as 'hamzazaheer' between August 12 and 21, 2024, with the intent to steal login credentials and install persistent backdoors in web applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 192d ago How this analysis works

Timeline

2024-08-12
NCryptYo package published
2024-08-21
Last of the four malicious packages published
2026-02-24
Cybersecurity news articles published about the attack

More articles in this cluster (3)

Following this threat?

Track DOMOAuth2_ in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed