Cybersecuritynews
Supply Chain Attack Targets ASP.NET Developers via Malicious NuGet Packages
First seen 24 Feb 2026, 18:11 UTC
•

•85% similarity
•29.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A supply chain attack has been identified, targeting ASP.NET developers through four malicious NuGet packages. The packages, named NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_, were published by a threat actor known as 'hamzazaheer' between August 12 and 21, 2024, with the intent to steal login credentials and install persistent backdoors in web applications.
ThreatCluster AI
How this analysis works
Timeline
2024-08-12
NCryptYo package published
2024-08-21
Last of the four malicious packages published
2026-02-24
Cybersecurity news articles published about the attack