Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
ID: 8f267e8e-81ed-57d6-ab2f-a50481fbed10
STIX ID: report--8f267e8e-81ed-57d6-ab2f-a50481fbed10
Feed Name: The Hacker News
Researchers discovered a NuGet typosquat package ('Newtonsoftt.Json.Net') that trojanizes Newtonsoft.Json to specifically target Digitain's FG-Crash betting backend: it activates when JsonConvert.DefaultSettings is assigned, introduces randomized delays to evade detection, rigs game results, and exfiltrates data to 185.126.237.64:5341 using header X-Seq-ApiKey:theperfectheist2025; seven versions were published (11.0.4–11.0.11), the package was downloaded ~1,200 times, and recommended mitigations include removing the package, blocking the C2, and pinning Newtonsoft.Json to a known-good version.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
