The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
JFrog Security Research uncovered a targeted NuGet typosquatting attack using a package named 'Newtonsoftt.Json.Net' (double 't') that impersonates the popular Newtonsoft.Json library. The malicious package ships a trojanized JSON fork bundled with HarmonyLib and a payload DLL specifically targeting Digitain's FG-Crash betting game. It uses a delayed Harmony patch to rig the game's GenerateGameResult method, manipulating crash multipliers on a deterministic schedule only the attacker knows. Seven versions were published across three generations, evolving from a local-only proof-of-concept to a version that exfiltrates rigged results to a C2 server disguised as Seq structured logging traffic. The package works normally for all non-targeted developers, making it nearly undetectable. Digitain confirmed awareness and resolution of the issue, though the full production impact is unknown. Remediation steps include removing the package, purging caches, blocking the C2 IP, and pinning legitimate package versions.