JFrog
Read post

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

JFrog Security Research uncovered a targeted NuGet typosquatting attack using a package named 'Newtonsoftt.Json.Net' (double 't') that impersonates the popular Newtonsoft.Json library. The malicious package ships a trojanized JSON fork bundled with HarmonyLib and a payload DLL specifically targeting Digitain's FG-Crash betting game. It uses a delayed Harmony patch to rig the game's GenerateGameResult method, manipulating crash multipliers on a deterministic schedule only the attacker knows. Seven versions were published across three generations, evolving from a local-only proof-of-concept to a version that exfiltrates rigged results to a C2 server disguised as Seq structured logging traffic. The package works normally for all non-targeted developers, making it nearly undetectable. Digitain confirmed awareness and resolution of the issue, though the full production impact is unknown. Remediation steps include removing the package, purging caches, blocking the C2 IP, and pinning legitimate package versions.

    #security#malware#nuget
Jul 21•14m read time•From jfrog.com
Post cover image
Table of contents
The Bait: A Working JSON Library with a Forged IdentityThe Evolution: Seven Versions, One Trojan, Three GenerationsThe Trigger: A Booby-Trapped Property SetterThe Patch: Rigging GenerateGameResultExfiltration: Traffic Disguised as Seq LoggingObfuscation: Patterns Across GenerationsWho is Affected by This NuGet Typosquat Attack?Remediation stepsDigitain’s ResponseTakeawaysIOCs
24 Impressions
JFrog's image
JFrog

JFrog is a leading provider of DevOps and software distribution solutions, offering tools for artifa...

22 Followers

•

126 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard