{"id":16986,"date":"2026-07-22T22:55:31","date_gmt":"2026-07-22T22:55:31","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=16986"},"modified":"2026-07-22T22:55:31","modified_gmt":"2026-07-22T22:55:31","slug":"malicious-nuget-typosquat-targets-digitain-betting-platform-and-rigs-sport-outcomes","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=16986","title":{"rendered":"Malicious NuGet Typosquat Targets Digitain Betting Platform and Rigs Sport Outcomes"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">JFrog Safety Analysis has disclosed a precision supply-chain assault by which a typosquatted NuGet bundle, <code>Newtonsoftt.Json.Internet<\/code>, impersonated the ever-present <code>Newtonsoft.Json<\/code> library whereas secretly rigging recreation outcomes at on-line betting operator Digitain. <\/p>\n<p class=\"wp-block-paragraph\">Not like typical info-stealers that harvest credentials indiscriminately, this trojan capabilities as a completely operational JSON library for each host besides its single meant goal.<\/p>\n<h2 id=\"h-malicious-nuget-typosquat-targets-digitain-betting-platform\" class=\"wp-block-heading\"><strong>Malicious NuGet Typosquat Targets Digitain Betting Platform<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The malicious bundle\u2019s <code>.nuspec<\/code> metadata cast the identification of James Newton-King, pointed on to the official Json.NET challenge URL, and used a plausible-looking 11.0.x model scheme. It differed from the real library by solely a doubled \u201ct\u201d and a <code>.Internet<\/code> suffix. <\/p>\n<p class=\"wp-block-paragraph\">Underneath <code>lib\/net8.0\/<\/code>, it shipped a trojanized fork of <code>Newtonsoft.Json<\/code> 13.0.3 alongside a payload DLL and the official <code>HarmonyLib<\/code> runtime-patching library, all designed to auto-load into host processes.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj03uh5gNjGEJs6N8EQBXqios2fx1d11H4u-AJy_n9zB-tLgvOIY5ALZwj5e4-Z0zt939h_cnrK9k8xYypqagwqgQCIfMr3I8MHqUoKf2JDD8yu8w9_J5VCtVXZXlU1OjzQWp5YWe-fz1NqMfFJw75_VQcb4tNCrhgKuDQV0T1A221obgIHGX4wYZOrmQg\/s1600\/NuGet-typesquat-attack-image3.webp\" alt=\"Package search result page.\"\/><figcaption class=\"wp-element-caption\">Package deal search outcome web page. (Picture Supply: jfrog.com)<\/figcaption><\/figure>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhuiawNmcZ3JXzU3Z5d5jazJgdS_8MTLCVD6YzlHXxldTiwvP4L0Bb2ejIiA5lqm7nL5_kfcwSvhvoj2mxlpBsvuK-4UD6POfwV7oZgbxd7gClnricXoPwY_WyE3x8o0Yh0kQmQcX0dTIXqnbkAbmhwelv9JVLnQ_UxSv-YiL2c0EsA4rEVzmEF5fp0rCA\/s1600\/NuGet-typesquat-attack-image7.webp\" alt=\"Unlisted package details page\"\/><figcaption class=\"wp-element-caption\">Unlisted bundle particulars web page (Picture Supply: jfrog.com)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">Crucially, the bundle\u2019s <code>.nuspec<\/code> file repeatedly leaked an inside TFS repository URL belonging to Digitain\u2019s \u201cBetOnGames \/ FG-Crash\u201d challenge\u2014successfully naming the goal seven instances throughout seven revealed variations. <\/p>\n<p class=\"wp-block-paragraph\">This diploma of specificity highlights how menace actors leverage <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/asyncapi-supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">provide chain assaults<\/a> to execute surgical company fraud somewhat than opportunistic information theft.<\/p>\n<p class=\"wp-block-paragraph\">The trojan prompts solely when a number software assigns <code>JsonConvert.DefaultSettings<\/code>, silently swapping the contract resolver whereas arming a Concord patch on a delayed timer. Within the newest era, this delay is about to 10 minutes, making certain activation happens lengthy after software startup when diagnostic logs seem clear.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiiYWjq6klrMNepWP_TTh8MnX-1f0sOxLOdFwP-FdgRxy339NfhIfNdn-lqqhv2-nCusnlKUggMEokIGtEvaIMCPzEpQcPZKlY25LgrYqHWhFV7YWUVE-hALhoicTpePKp5qRQTUIwYUfqYgfkJScPucZIWGZD6RfN7VFKo82QDrbO5rVrXvcbCyDhARpU\/s1600\/NuGet-Typesquatting-Diagram1.webp\" alt=\"Multi-generation attack flow chart\"\/><figcaption class=\"wp-element-caption\">Multi-generation assault circulation chart (Picture Supply: jfrog.com)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\">As soon as triggered, the payload patches <code>Digitain.FG.SharedCrash.GameLogic.SharedCrashRules.GenerateGameResult<\/code>, manipulating the crash-game coefficient utilizing schedules keyed thus far, time, and a particular profile for the 22:00 UTC window. The rigging is bounded to a hard and fast variety of rounds earlier than the trojan unpatches itself to keep away from ongoing detection.<\/p>\n<p class=\"wp-block-paragraph\">The attacker iterated throughout seven bundle variations revealed between August and October 2025. The marketing campaign progressed from a local-only proof of idea to an obfuscated exfiltration channel, and eventually to an unobfuscated manufacturing construct:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<td><strong>Era<\/strong><\/td>\n<td><strong>Variations Printed<\/strong><\/td>\n<td><strong>Core Payload Functionality<\/strong><\/td>\n<td><strong>Utilized Obfuscation<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Gen-1<\/strong><\/td>\n<td>11.0.7, 11.0.8<\/td>\n<td>Console-only rigging, no networking calls<\/td>\n<td>Dotfuscator<\/td>\n<\/tr>\n<tr>\n<td><strong>Gen-2<\/strong><\/td>\n<td>11.0.4, 11.0.5, 11.0.9<\/td>\n<td>Reflection-based exfiltration pipeline<\/td>\n<td>ConfuserEx (heavy)<\/td>\n<\/tr>\n<tr>\n<td><strong>Gen-3<\/strong><\/td>\n<td>11.0.10, 11.0.11<\/td>\n<td>Direct HTTP postfix exfiltration to C2<\/td>\n<td>Gentle to none<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p class=\"wp-block-paragraph\">Gen-3 exfiltrated rigged outcomes to a hardcoded command-and-control server disguised as a Seq structured-logging endpoint, utilizing the header <code>X-Seq-ApiKey: theperfectheist2025<\/code> to mix malicious visitors with regular software telemetry.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh0RmJNLcl9iXGY5GV6idMxUDoZ2FyvoSQ51WaoJDBc11etMmJ7Auki1QWAx354_dGkPNBKvX24enZQ4qnyozWQ8wkmb1824PUDaNlfx0pRTPWwklCp3lAf8hrztH_EV7rShXFFbmVEeezkpdYwMevovtuTvKPX2tipUxifbXjDDs9MPbTKv7qDxwPASyM\/s1600\/NuGet-Typesquatting-Diagram2.webp\" alt=\"Trojanized package execution flow\"\/><figcaption class=\"wp-element-caption\">Trojanized bundle execution circulation (Picture Supply: jfrog.com)<\/figcaption><\/figure>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/jfrog.com\/blog\/nuget-typosquat-targets-betting-platform\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">JFrog disclosed the malicious bundle<\/a> to Digitain on July 7, 2026, and the corporate confirmed on July 9 that it was already conscious of the problem and had resolved it.<\/p>\n<p class=\"wp-block-paragraph\">Though the bundle was unlisted from NuGet search after October 2025, its artifacts remained downloadable. This persistence highlights the continued <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/search?q=https:\/\/gbhackers.com\/malicious-npm-packages\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious bundle dangers<\/a> throughout open-source ecosystems.<\/p>\n<h4 id=\"h-key-defensive-actions\" class=\"wp-block-heading\"><strong>Key Defensive Actions:<\/strong><\/h4>\n<ul class=\"wp-block-list\">\n<li><strong>Take away Dependencies:<\/strong> Delete <code>Newtonsoftt.Json.Internet<\/code> from all challenge manifests and world bundle caches (<code>~\/.nuget\/packages<\/code>).<\/li>\n<li><strong>Block C2 Infrastructure:<\/strong> Prohibit outbound visitors to the C2 IP <code>185.126.237.64:5341<\/code>.<\/li>\n<li><strong>Lock Dependencies:<\/strong> Pin <code>Newtonsoft.Json<\/code> variations utilizing lockfiles to forestall unintended typosquatting installations.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 87%,rgb(169,184,195) 100%)\"><strong>\ud835\uddd4\ud835\udddc \ud835\udde6\ud835\udde2\ud835\uddd6 \ud835\ude03\ud835\ude00 \ud835\udde0\ud835\uddd7\ud835\udde5 \ud835\ude03\ud835\ude00 \ud835\udde0\ud835\udde6\ud835\udde6\ud835\udde3 Which is Finest in 2026? Evaluate prices, Automation, and response:\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/underdefense.com\/ai-soc-vs-mdr-vs-mssp-scoring-table-pricing-data-response-proof\/?utm_source=cybersecuritynews.com&amp;utm_medium=online_media&amp;utm_campaign=csn_linkedin_newsletter_ai_soc_vs_mdr_vs_mssp_july_2026\" target=\"_blank\" rel=\"noreferrer noopener\">Obtain Free Information<\/a><\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>JFrog Safety Analysis has disclosed a precision supply-chain assault by which a typosquatted NuGet bundle, Newtonsoftt.Json.Internet, impersonated the ever-present Newtonsoft.Json library whereas secretly rigging recreation outcomes at on-line betting operator Digitain. Not like typical info-stealers that harvest credentials indiscriminately, this trojan capabilities as a completely operational JSON library for each host besides its single meant [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16988,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[7518,9888,89,1166,9886,630,95,9889,303,9887],"class_list":["post-16986","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-betting","tag-digitain","tag-game","tag-malicious","tag-nuget","tag-platform","tag-results","tag-rigs","tag-targets","tag-typosquat"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16986","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16986"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16986\/revisions"}],"predecessor-version":[{"id":16987,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16986\/revisions\/16987"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/16988"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16986"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16986"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16986"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-07-23 02:46:05 UTC -->