
⚠️ Work in Progress — The project is actively developed. Core scanning engine is functional; database persistence, caching, and full test coverage are planned for upcoming iterations.
NuReaper is a .NET 8 backend API that automatically analyzes the security of NuGet packages. You provide a link to any NuGet package, and the system recursively downloads its entire dependency tree, decompiles the compiled code, and scans every method for malicious patterns — returning a detailed threat report.
🔍 For non-technical readers: Think of it like installing an app on your phone. Along with it, dozens of smaller libraries get installed automatically. NuReaper inspects every single one of them — looking at the actual compiled binary code — and detects whether any of them try to connect to suspicious servers, execute hidden code, or obfuscate their true behavior.
Send a single HTTP request with a NuGet package URL, and NuReaper will:
.nupkg file and computes its SHA-256 hashThe engine analyzes code at the IL (Intermediate Language) instruction level and recognizes 7 patterns characteristic of malicious software:
| # | Pattern | Description |
|---|---|---|
| 1 | Direct API Call | Suspicious string immediately used in a network call |
| 2 | String Assigned | URL assigned to a variable, then passed to a network call |
| 3 | String Construction | URL built by concatenation ("http://" + var + "/path") — obfuscation technique |
| 4 | String Interpolation | URL assembled via interpolation ($"{part1}{part2}") |
| 5 | Char-Only Interpolation | URL built char-by-char from a char array — advanced obfuscation |
| 6 | DefaultInterpolatedStringHandler | Low-level interpolation mechanism used to hide strings from static analysis |
| 7 | Bare API Calls | Direct network calls without explicit strings (TcpClient.Connect, Socket.Connect, Process.Start) |
Network: HttpClient, WebClient, DNS, TcpClient, WebSocket
Execution: Process.Start, Assembly.Load, Activator.CreateInstance
Low-level: DllImport, VirtualAlloc, CreateThread, NtCreateThreadEx
System: ManagementObjectSearcher (WMI)
String-based: Concatenation, CharArray, Interpolation, StringBuilder
Suspicious: URL, IP address, .onion address, Base64
The scoring algorithm accounts for:
POST /api/PackageScanScans the given NuGet package along with its full dependency tree.
Request:
{
"url": "https://www.nuget.org/packages/System.Net.Http/4.3.4"
}
Response:
{
"rootPackageName": "System.Net.Http",
"rootPackageVersion": "4.3.4",
"totalPackages": 12,
"totalFindingsFromAllPackages": 5,
"threatLevelAllPackages": 47.5,
"scannedTimeAllPackages": "2026-03-25T12:00:00Z",
"packages": [
{
"packageName": "System.Net.Http",
"version": "4.3.4",
"sha256Hash": "abc123...",
"threatLevel": 35.0,
"totalFindings": 3,
"findings": [
{
"type": "HttpClientCall",
"confidenceScore": 95.0,
"dangerLevel": 60.0,
"evidence": "http://example.com/payload",
"location": "MyClass::SendData",
"hopDepth": 0,
"flowTrace": "[Pattern1] Direct API call using string..."
}
]
}
],
"dependencyGraph": {
"rootPackage": "[email protected]",
"nodes": [...],
"edges": [...],
"cycles": [...]
}
}
Built on Clean Architecture with a strict separation of concerns:
NuReaperBackend/
├── NuReaper.Api/ # API layer — controllers, middleware, startup
├── NuReaper.Application/ # Application layer — commands, interfaces, DTOs, validation
├── NuReaper.Domain/ # Domain core — entities, enums, abstractions
├── NuReaper.Infrastructure/ # Implementations — scanners, parsers, repositories
│ └── Repositories/
│ ├── Scanners/ # IL analysis engine
│ │ ├── Analysis/ # ScanModule, ScanMethod, NetworkApiCallScan
│ │ ├── Detectors/ # 7 pattern detectors (Pattern1–Pattern7)
│ │ ├── Patterns/ # PatternRegistry (regex: URL, IP, .onion, Base64)
│ │ ├── RiskCalculation/# Threat scoring algorithm
│ │ ├── Finders/ # Locating API calls within IL instructions
│ │ ├── VariableAnalysis/# Tracking variable values across IL
│ │ └── StringAnalysis/ # Reconstructing strings from fragments
│ ├── Parsers/ # .nuspec file parsing
│ ├── GraphBuilders/ # Dependency graph construction (BFS + recursion)
│ └── FileHelpers/ # Download, extract, SHA-256
└── Docker/
├── Dockerfile
└── docker-compose.yml
| Area | Technology / Pattern |
|---|---|
| Architecture | Clean Architecture |
| Inter-layer communication | CQRS + MediatR |
| IL code analysis | dnlib |
| Input validation | FluentValidation + MediatR Pipeline Behavior |
| Object mapping | AutoMapper |
| Logging | Serilog (console + rolling daily file) |
| API documentation | Swagger / OpenAPI |
| Database | Entity Framework Core + MySQL (Pomelo) |
| HTTP | IHttpClientFactory with connection pooling |
| Containerization | Docker + Docker Compose |
| Testing | xUnit + Moq |
Package URL
│
▼
DependencyGraphBuilder ← builds dependency graph from .nuspec files
│ (recursion + BFS, cycle detection)
▼
List of unique packages
│
▼ (parallel, SemaphoreSlim — CPU-1 threads)
NetworkApiCallScan per package
├── DownloadPackageAsync ← fetches .nupkg
├── CalculateSha256 ← integrity verification
├── ExtractNupkgAsync ← unpacks the archive
└── GetAssemblyFiles ← lists .dll files
│
▼ (Parallel.ForEachAsync)
ScanModule (per .dll)
│
▼ (Parallel.ForEach — all types and methods)
ScanMethod (per method)
│
▼ (7 pattern detectors)
Pattern1..7 → FindingSummaryDto
│
▼
CalculateThreatLevel ← score 0–100
│
▼
ScanPackageResultResponse
| Package | Purpose |
|---|---|
dnlib | .NET IL decompilation and analysis |
MediatR | CQRS — command/query pipeline |
FluentValidation | Request validation |
AutoMapper | Cross-layer object mapping |
Serilog | Structured logging |
Pomelo.EntityFrameworkCore.MySql | MySQL ORM |
Swashbuckle.AspNetCore | Swagger UI |
xUnit + Moq | Unit testing |
This project is available under the PolyForm Noncommercial License 1.0.0, commercial use is prohibited. For commercial licensing or inquiries, contact: [email protected]