Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Ukraine aid group targeted through fake Zoom meetings and weaponized PDF files

UK recognizes Apple, Google as having ‘strategic market positions’, opening door to further regulation

GM’s internal reforms will focus on AI and autonomous driving

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fake Nethereum NuGet package uses homoglyph trick to steal crypto wallet keys
Identity

Fake Nethereum NuGet package uses homoglyph trick to steal crypto wallet keys

userBy userOctober 22, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 22, 2025Ravi LakshmananCryptocurrency/Software Integrity

Cybersecurity researchers have discovered a new supply chain attack targeting the popular Ethereum .NET integration platform Nethereum’s NuGet package manager with malicious typosquats to steal victims’ cryptocurrency wallet keys.

According to security firm Socket, the package ‘Netherеum.All’ was found to contain functionality that decodes command and control (C2) endpoints and leaks mnemonic phrases, private keys, and keystore data.

This library was uploaded on October 16, 2025 by a user named ‘nethereumgroup’. Four days later, it was removed from NuGet for violating the terms of service.

What’s notable about the NuGet package is that it replaces the last occurrence of the letter “e” with the Cyrillic isomorphic letter “e” (U+0435) to trick unsuspecting developers into downloading it.

DFIR retainer service

In a further attempt to increase the credibility of the package, the attackers artificially inflated the download numbers, claiming that the package had been downloaded 11.7 million times. This is a big red flag considering it’s unlikely that a brand new library would record such high numbers in such a short period of time.

“An attacker could publish many versions, script the download of each .nupkg via a v3 flat container or loop nuget.exe, and restore dotnet using the no-cache option from the cloud host,” said security researcher Kirill Boychenko. “Rotating IPs and user agents and parallelizing requests improves volume while avoiding client caching.”

“The result is packages that look ‘popular’ and rank well in searches sorted by relevance, giving developers false evidence when they glance at the numbers.”

The main payload in the NuGet package is inside a function named EIP70221TransactionService.Shuffle that parses the XOR encoded string to extract the C2 server (solananetworkinstance).[.]info/api/gads) and exfiltrate the wallet’s sensitive data to the attacker.

The threat actor was found to have uploaded another NuGet package called ‘NethereumNet’ with the same malicious functionality earlier in the month. This has already been removed by the NuGet security team.

CIS build kit

This is not the first isomorphic typosquat discovered in the NuGet repository. In July 2024, ReversingLabs documented details of several packages that masqueraded as legitimate packages by replacing certain elements with equivalent elements to evade casual inspection.

Unlike other open source package repositories such as PyPI, npm, Maven Central, Go Module, and RubyGems that impose restrictions on naming schemes to ASCII, NuGet has no such restrictions other than prohibiting spaces and unsafe URL characters, opening the door to abuse.

To mitigate such risks, users should carefully examine libraries before downloading them, including verifying the identity of the publisher and sudden spikes in downloads, and monitoring for unusual network traffic.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMicrosoft 365 Copilot trial will save NHS significant time
Next Article Closing the remediation gap: Introducing Penera Resolve
user
  • Website

Related Posts

Ukraine aid group targeted through fake Zoom meetings and weaponized PDF files

October 22, 2025

Weeks after Microsoft’s July patch, Chinese attackers exploit ToolShell SharePoint flaw

October 22, 2025

Closing the remediation gap: Introducing Penera Resolve

October 22, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ukraine aid group targeted through fake Zoom meetings and weaponized PDF files

UK recognizes Apple, Google as having ‘strategic market positions’, opening door to further regulation

GM’s internal reforms will focus on AI and autonomous driving

Samsung takes on Apple’s Vision Pro with new Galaxy XR headset

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.