JFrog Safety Analysis has disclosed a precision supply-chain assault by which a typosquatted NuGet bundle, Newtonsoftt.Json.Internet, impersonated the ever-present Newtonsoft.Json library whereas secretly rigging recreation outcomes at on-line betting operator Digitain.
Not like typical info-stealers that harvest credentials indiscriminately, this trojan capabilities as a completely operational JSON library for each host besides its single meant goal.
Malicious NuGet Typosquat Targets Digitain Betting Platform
The malicious bundle’s .nuspec metadata cast the identification of James Newton-King, pointed on to the official Json.NET challenge URL, and used a plausible-looking 11.0.x model scheme. It differed from the real library by solely a doubled “t” and a .Internet suffix.
Underneath lib/net8.0/, it shipped a trojanized fork of Newtonsoft.Json 13.0.3 alongside a payload DLL and the official HarmonyLib runtime-patching library, all designed to auto-load into host processes.
Crucially, the bundle’s .nuspec file repeatedly leaked an inside TFS repository URL belonging to Digitain’s “BetOnGames / FG-Crash” challenge—successfully naming the goal seven instances throughout seven revealed variations.
This diploma of specificity highlights how menace actors leverage provide chain assaults to execute surgical company fraud somewhat than opportunistic information theft.
The trojan prompts solely when a number software assigns JsonConvert.DefaultSettings, silently swapping the contract resolver whereas arming a Concord patch on a delayed timer. Within the newest era, this delay is about to 10 minutes, making certain activation happens lengthy after software startup when diagnostic logs seem clear.
As soon as triggered, the payload patches Digitain.FG.SharedCrash.GameLogic.SharedCrashRules.GenerateGameResult, manipulating the crash-game coefficient utilizing schedules keyed thus far, time, and a particular profile for the 22:00 UTC window. The rigging is bounded to a hard and fast variety of rounds earlier than the trojan unpatches itself to keep away from ongoing detection.
The attacker iterated throughout seven bundle variations revealed between August and October 2025. The marketing campaign progressed from a local-only proof of idea to an obfuscated exfiltration channel, and eventually to an unobfuscated manufacturing construct:
| Era | Variations Printed | Core Payload Functionality | Utilized Obfuscation |
| Gen-1 | 11.0.7, 11.0.8 | Console-only rigging, no networking calls | Dotfuscator |
| Gen-2 | 11.0.4, 11.0.5, 11.0.9 | Reflection-based exfiltration pipeline | ConfuserEx (heavy) |
| Gen-3 | 11.0.10, 11.0.11 | Direct HTTP postfix exfiltration to C2 | Gentle to none |
Gen-3 exfiltrated rigged outcomes to a hardcoded command-and-control server disguised as a Seq structured-logging endpoint, utilizing the header X-Seq-ApiKey: theperfectheist2025 to mix malicious visitors with regular software telemetry.
JFrog disclosed the malicious bundle to Digitain on July 7, 2026, and the corporate confirmed on July 9 that it was already conscious of the problem and had resolved it.
Though the bundle was unlisted from NuGet search after October 2025, its artifacts remained downloadable. This persistence highlights the continued malicious bundle dangers throughout open-source ecosystems.
Key Defensive Actions:
- Take away Dependencies: Delete
Newtonsoftt.Json.Internetfrom all challenge manifests and world bundle caches (~/.nuget/packages). - Block C2 Infrastructure: Prohibit outbound visitors to the C2 IP
185.126.237.64:5341. - Lock Dependencies: Pin
Newtonsoft.Jsonvariations utilizing lockfiles to forestall unintended typosquatting installations.
𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Finest in 2026? Evaluate prices, Automation, and response: Obtain Free Information







