• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Sport Outcomes

Admin by Admin
July 22, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


JFrog Safety Analysis has disclosed a precision supply-chain assault by which a typosquatted NuGet bundle, Newtonsoftt.Json.Internet, impersonated the ever-present Newtonsoft.Json library whereas secretly rigging recreation outcomes at on-line betting operator Digitain.

Not like typical info-stealers that harvest credentials indiscriminately, this trojan capabilities as a completely operational JSON library for each host besides its single meant goal.

Malicious NuGet Typosquat Targets Digitain Betting Platform

The malicious bundle’s .nuspec metadata cast the identification of James Newton-King, pointed on to the official Json.NET challenge URL, and used a plausible-looking 11.0.x model scheme. It differed from the real library by solely a doubled “t” and a .Internet suffix.

Underneath lib/net8.0/, it shipped a trojanized fork of Newtonsoft.Json 13.0.3 alongside a payload DLL and the official HarmonyLib runtime-patching library, all designed to auto-load into host processes.

Package search result page.
Package deal search outcome web page. (Picture Supply: jfrog.com)
Unlisted package details page
Unlisted bundle particulars web page (Picture Supply: jfrog.com)

Crucially, the bundle’s .nuspec file repeatedly leaked an inside TFS repository URL belonging to Digitain’s “BetOnGames / FG-Crash” challenge—successfully naming the goal seven instances throughout seven revealed variations.

This diploma of specificity highlights how menace actors leverage provide chain assaults to execute surgical company fraud somewhat than opportunistic information theft.

The trojan prompts solely when a number software assigns JsonConvert.DefaultSettings, silently swapping the contract resolver whereas arming a Concord patch on a delayed timer. Within the newest era, this delay is about to 10 minutes, making certain activation happens lengthy after software startup when diagnostic logs seem clear.

Multi-generation attack flow chart
Multi-generation assault circulation chart (Picture Supply: jfrog.com)

As soon as triggered, the payload patches Digitain.FG.SharedCrash.GameLogic.SharedCrashRules.GenerateGameResult, manipulating the crash-game coefficient utilizing schedules keyed thus far, time, and a particular profile for the 22:00 UTC window. The rigging is bounded to a hard and fast variety of rounds earlier than the trojan unpatches itself to keep away from ongoing detection.

The attacker iterated throughout seven bundle variations revealed between August and October 2025. The marketing campaign progressed from a local-only proof of idea to an obfuscated exfiltration channel, and eventually to an unobfuscated manufacturing construct:

Era Variations Printed Core Payload Functionality Utilized Obfuscation
Gen-1 11.0.7, 11.0.8 Console-only rigging, no networking calls Dotfuscator
Gen-2 11.0.4, 11.0.5, 11.0.9 Reflection-based exfiltration pipeline ConfuserEx (heavy)
Gen-3 11.0.10, 11.0.11 Direct HTTP postfix exfiltration to C2 Gentle to none

Gen-3 exfiltrated rigged outcomes to a hardcoded command-and-control server disguised as a Seq structured-logging endpoint, utilizing the header X-Seq-ApiKey: theperfectheist2025 to mix malicious visitors with regular software telemetry.

Trojanized package execution flow
Trojanized bundle execution circulation (Picture Supply: jfrog.com)

JFrog disclosed the malicious bundle to Digitain on July 7, 2026, and the corporate confirmed on July 9 that it was already conscious of the problem and had resolved it.

Though the bundle was unlisted from NuGet search after October 2025, its artifacts remained downloadable. This persistence highlights the continued malicious bundle dangers throughout open-source ecosystems.

Key Defensive Actions:

  • Take away Dependencies: Delete Newtonsoftt.Json.Internet from all challenge manifests and world bundle caches (~/.nuget/packages).
  • Block C2 Infrastructure: Prohibit outbound visitors to the C2 IP 185.126.237.64:5341.
  • Lock Dependencies: Pin Newtonsoft.Json variations utilizing lockfiles to forestall unintended typosquatting installations.

𝗔𝗜 𝗦𝗢𝗖 𝘃𝘀 𝗠𝗗𝗥 𝘃𝘀 𝗠𝗦𝗦𝗣 Which is Finest in 2026? Evaluate prices, Automation, and response: Obtain Free Information

Tags: bettingDigitainGameMaliciousNuGetPlatformresultsRigstargetsTyposquat
Admin

Admin

Next Post
Lower Information Errors, Pace Compliance

Lower Information Errors, Pace Compliance

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Ideas on Streaming Companies: 2024 Version

Ideas on Streaming Companies: 2024 Version

June 16, 2025
Prime 10 Most Standard Companies on TaskRabbit in 2025

Prime 10 Most Standard Companies on TaskRabbit in 2025

March 25, 2025
Maximize Your Kitchen with the Finest Organizers – Chefio

Maximize Your Kitchen with the Finest Organizers – Chefio

May 4, 2025
TikTok’s Clock Retains Operating: Trump Extends Sale Deadline Once more

TikTok’s Clock Retains Operating: Trump Extends Sale Deadline Once more

June 19, 2025
Supplier of covert surveillance app spills passwords for 62,000 customers

Supplier of covert surveillance app spills passwords for 62,000 customers

July 7, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Lower Information Errors, Pace Compliance

Lower Information Errors, Pace Compliance

July 22, 2026
Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Sport Outcomes

Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Sport Outcomes

July 22, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved