logo

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

ID: 8f267e8e-81ed-57d6-ab2f-a50481fbed10

STIX ID: report--8f267e8e-81ed-57d6-ab2f-a50481fbed10

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: [email protected] (The Hacker News)

...
...

Researchers discovered a NuGet typosquat package ('Newtonsoftt.Json.Net') that trojanizes Newtonsoft.Json to specifically target Digitain's FG-Crash betting backend: it activates when JsonConvert.DefaultSettings is assigned, introduces randomized delays to evade detection, rigs game results, and exfiltrates data to 185.126.237.64:5341 using header X-Seq-ApiKey:theperfectheist2025; seven versions were published (11.0.4–11.0.11), the package was downloaded ~1,200 times, and recommended mitigations include removing the package, blocking the C2, and pinning Newtonsoft.Json to a known-good version.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.