Supply Chain Attack Targets ASP.NET Developers via Malicious NuGet Packages

Supply Chain Attack Targets ASP.NET Developers via Malicious NuGet Packages

First seen 24 Feb 2026, 18:11 UTC GbhackersCybersecuritynewsScworld 85% similarity 29.2

Article Content

Browse articles
ThreatCluster

A supply chain attack has been identified, targeting ASP.NET developers through four malicious NuGet packages. The packages, named NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_, were published by a threat actor known as 'hamzazaheer' between August 12 and 21, 2024, with the intent to steal login credentials and install persistent backdoors in web applications.

ThreatCluster AI How this analysis works

Timeline

2024-08-12
NCryptYo package published
2024-08-21
Last of the four malicious packages published
2026-02-24
Cybersecurity news articles published about the attack

Community

Browse all →

Tracked Entities in This Story