PULSE NAME
5 Malicious NuGet Packages Impersonate Chinese UI Libraries to Distribute Crypto Wallet and Credential Stealer
WHITE AlienVault 2026-05-07 Modified: 2026-05-08
13
IOCs
MEDIUM VOLUME
Five malicious NuGet packages published under account bmrxntfj impersonate Chinese .NET libraries to deploy an infostealer targeting browser credentials, cryptocurrency wallets, SSH keys, and local files. The packages typosquat legitimate Chinese UI and infrastructure libraries, grafting .NET Reactor-protected payloads onto decompiled legitimate code. The campaign uses version rotation to evade hash-based detection, with 219 of 224 total versions unlisted but fetchable. The stealer targets 12 browsers, 8 desktop crypto wallets, and 5 browser wallet extensions, exfiltrating data to a newly-registered C2 domain. With approximately 65,000 downloads across all versions, the campaign puts tens of thousands of developer workstations and CI/CD build servers at risk. The payload executes through .NET module initializers, hooks the CLR JIT compiler, and supports cross-platform infection including Linux and macOS infrastructure.
Indicators of Compromise (13)
All FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 efb675de4b3af3dac3c9cae91075fd7cc2f4f98e 2026-05-07
FileHash-SHA256 019e6c2cf58386039133981f3377b085fbd70c98ae8613c7c6a4f10a9f2d9824 2026-05-07
FileHash-SHA256 34e2d63b5db7e24c808711c2ca0c0a42afde97a0086d7d81609110c002d18d7c 2026-05-07
FileHash-SHA256 596c453c9dbb7240f1ce05cc025496524ce7c538c23a9b2171174bf32b5691a1 2026-05-07
FileHash-SHA256 8f7aa15c77bde94087bb74dfc072e25212797b313731b4cad0ded3e152268dcf 2026-05-07
FileHash-SHA256 b8543b2a1ad8862ebfef18924cf5444d2adfee996939963f4fc2748c582cf9a9 2026-05-07
FileHash-SHA256 b8fa1b2fade45304c003909e375d2519ea447b498b7d93fe7c50db014d30f4fa 2026-05-07
FileHash-SHA256 e1869d6571894f058dd4ab2b66f060628dc364ee8e29afbd2323c95e5002fb8e 2026-05-07
URL https://dns-providersa2.com/check 2026-05-07
URL https://dns-providersa2.com/upload 2026-05-07
domain dns-providersa2.com 2026-05-07
domain justdotrip.com 2026-05-07
hostname git.justdotrip.com 2026-05-07