The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results
Blog post from JFrog
A typosquatted NuGet package named Newtonsoftt.Json.Net, discovered by the JFrog Security Research team, has been masquerading as the popular Newtonsoft.Json library, delivering a trojanized fork aimed specifically at Digitain, an online betting platform. This malicious package, which was available from August to October 2025, is a sophisticated fraud tool that operates as a functional JSON library for most users, but upon initialization, it targets systems that expose specific backend methods, exfiltrating rigged game results to an attacker-controlled server. The package's metadata was crafted to impersonate the original library, using similar versioning and author details to avoid detection. Over its seven versions, the trojan evolved through three generations, each iteration refining its obfuscation, rigging strategy, and exfiltration path. The attacker utilized HarmonyLib to patch game logic, altering game outcomes to execute a controlled betting strategy, with exfiltration disguised as legitimate logging traffic. Though the package has been unlisted, artifacts remain accessible, highlighting the need for vigilance against such supply-chain attacks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.