malware nuget

grandrp-x-x

discovered 2026-07-14

NuGet DotnetTool downloader ("GrandRP") published under operator pepegit666. Assembly grandrp.dll, release tag "grandrp.su". Wraps gtaobus.pyc with pyarmor_runtime_015050; falls back to a hardcoded authenticated HTTP proxy for Google Sheets when direct access fails. On run it masquerades with a colored Russian console, sets AWS-style env vars, DoH-resolves GitHub hosts, and fetches the shared second-stage pepesoft.exe (Hugging Face -> GitHub Releases -> dormant BitTorrent). The payload writes host telemetry/inventory to Google Sheets and enforces an HWID/UUID ban-list kill switch. Only the [email protected] version was explicitly disclosed; other package versions were not enumerated in the source.

Threat types

data_exfiltration c2_agent

Malicious versions

  • unspecified

Campaigns

Indicators

Read the full analysis →