Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Trojanized NuGet Package Alters Online Betting Results

Trojanized NuGet Package Alters Online Betting Results

Posted on July 22, 2026 By CWS

Cybersecurity experts have identified an unusual NuGet package that deceptively rigs online game results on the Digitain platform. This package, titled “Newtonsoftt.Json.Net,” mimics the popular Newtonsoft.Json library and comes as a trojanized version. Released across seven versions, it has amassed approximately 1,200 downloads from the NuGet repository.

Background on the Trojanized Package

Masquerading as a legitimate JSON library, this package has been removed from search visibility by its creator, MagicalPuff96, yet remains downloadable. It specifically targets Digitain by rigging games and exfiltrating manipulated results to a rogue server using a unique header, according to JFrog researchers.

The package’s distribution includes versions 11.0.4 through 11.0.11, each containing the same trojanized core. The attack initiates when the host system sets JsonConvert.DefaultSettings, exploiting specific backend methods of the targeted entity.

Technical Details of the Attack

The malicious activity is triggered via a modified DefaultSettings property, designed to delay activation and evade detection. The primary goal is to compromise Digitain’s crash-game backend, sending rigged results to a designated IP address, disguised as regular telemetry data.

Throughout its iterations, the package evolved from a local proof of concept to a fully-fledged exfiltration tool, with varying degrees of obfuscation employed across versions. Notably, the final version, 11.0.11, lacks obfuscation, suggesting an accidental clean build release.

Impact and Response

Digitain, the sole target, operates the FG-Crash betting game, with evidence suggesting the attacker had access to internal repositories. The trojan activates only under specific conditions, thus not affecting most developers who unwittingly installed the package.

To mitigate the threat, it is advised to uninstall the package, block associated command-and-control addresses, and secure the Newtonsoft.Json library to trusted versions. Digitain has acknowledged the breach and is implementing corrective measures, though the full impact remains uncertain.

In conclusion, this incident underscores the risks associated with software supply chains, highlighting the importance of vigilance and proactive security practices in the face of evolving cyber threats.

The Hacker News Tags:cyber attack, Cybersecurity, Digitain, Exfiltration, game rigging, JFrog, JSON library, Malware, Newtonsoft.Json, NuGet, online betting, Software Security, supply chain attack, trojanized package, typosquatting

Post navigation

Previous Post: AI Exploits Highlight New Cybersecurity Challenges
Next Post: Hidden Comment Flaw in Azure DevOps Risks AI Exploitation

Related Posts

Microsoft Addresses Defender Exploit, Patch in Progress Microsoft Addresses Defender Exploit, Patch in Progress The Hacker News
Why Secrets in JavaScript Bundles are Still Being Missed Why Secrets in JavaScript Bundles are Still Being Missed The Hacker News
New Linux Malware Showboat Targets Middle East Telecom New Linux Malware Showboat Targets Middle East Telecom The Hacker News
Critical Vulnerabilities in FatFs Impact Millions of Devices Critical Vulnerabilities in FatFs Impact Millions of Devices The Hacker News
Critical SharePoint Vulnerability CVE-2026-50522 Exploited Critical SharePoint Vulnerability CVE-2026-50522 Exploited The Hacker News
New Konfety Malware Variant Evades Detection by Manipulating APKs and Dynamic Code New Konfety Malware Variant Evades Detection by Manipulating APKs and Dynamic Code The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AccuKnox Secures Top AI Startup Award for Security Excellence
  • Coca-Cola’s Fairlife Hit by Anubis Ransomware Attack
  • Law Enforcement Shuts Down Major Kratos Phishing Network
  • GolangGhost Malware Targets Crypto Professionals
  • Hidden Comment Flaw in Azure DevOps Risks AI Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AccuKnox Secures Top AI Startup Award for Security Excellence
  • Coca-Cola’s Fairlife Hit by Anubis Ransomware Attack
  • Law Enforcement Shuts Down Major Kratos Phishing Network
  • GolangGhost Malware Targets Crypto Professionals
  • Hidden Comment Flaw in Azure DevOps Risks AI Exploitation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark