Newtonsoftt.Json.Net trojanized fork rigs Digitain FG-Crash results
Malware Activity
Summary
Hide ▲
Show ▼
The Newtonsoftt.Json.Net package was found delivering a trojanized fork that can rig Digitain FG-Crash results and exfiltrate them, turning a routine library install into a targeted integrity attack. The package masquerades as Newtonsoft.Json for non-targets, but its malicious path only activates when the host reaches the FG-Crash backend method. The malicious versions span 11.0.4 through 11.0.11, published between August 13 and October 10, 2025. The payload sends rigged round results to 185.126.237[.]64:5341 with X-Seq-ApiKey: theperfectheist2025.
Related Happenings
Lazarus Group graphalgo recruitment-themed package campaign
Campaign
H score38
First: 12.02.2026 18:55
Last: 12.02.2026 18:55
Sources 1
About this happening:
The North Korea-linked Lazarus Group is running graphalgo, an active fake recruitment-themed package campaign that is targeting developers through npm and PyPI...
Lazarus Group graphalgo recruitment-themed package campaign
CampaignAbout this happening: The North Korea-linked Lazarus Group is running graphalgo, an active fake recruitment-themed package campaign that is targeting developers through npm and PyPI...
BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse
Malware Activity
H score39
First: 20.01.2026 20:41
Last: 20.01.2026 20:41
Sources 1
About this happening:
North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...
BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse
Malware ActivityAbout this happening: North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...
Latest development: 22.04.2026 17:48
North Korean actor Void Dokkaebi, aka Famous Chollima, is turning the Contagious Interview fake-job lure into a self-propagating software supply-chain infection that abuses compromised developer repositories, malicious VS Code tasks, and injected code to spread malware and steal credentials. The campaign targets developers seeking work, can hide a poisoned .vscode folder in committed code, and Trend Micro said it found more than 750 infected code repositories, more than 500 malicious VS Code task configurations, and 101 commit-tampering instances in March.
Tracer.Fody.NLog malicious NuGet wallet stealer
Malware Activity
H score30
First: 16.12.2025 17:39
Last: 16.12.2025 17:39
Sources 1
About this happening:
Tracer.Fody.NLog is a malicious NuGet package that steals Stratis wallet data and passwords from .NET projects, creating a supply-chain risk for developers and cryptoc...
Tracer.Fody.NLog malicious NuGet wallet stealer
Malware ActivityAbout this happening: Tracer.Fody.NLog is a malicious NuGet package that steals Stratis wallet data and passwords from .NET projects, creating a supply-chain risk for developers and cryptoc...
Timeline
-
22.07.2026 09:00 2 articles · 13d ago
NuGet typosquat Newtonsoftt.Json.Net targets Digitain's FG-Crash backend
Initial DisclosureA NuGet package named Newtonsoftt.Json.Net masquerades as Newtonsoft.Json and contains a trojanized fork that targets Digitain's FG-Crash crash-game backend. The payload only activates when JsonConvert.DefaultSettings is assigned, introduces a randomized delay to evade detection, and on targeted systems exfiltrates rigged round results to 185.126.237[.]64:5341 while using X-Seq-ApiKey: theperfectheist2025. The package was published in seven versions, 11.0.4 through 11.0.11, downloaded about 1,200 times, and its metadata leaked an internal Digitain repository URL seven times, suggesting access to FG-Crash source code. Digitain has said it was aware of the issue and had taken steps to resolve it.
Show sources
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library — thehackernews.com — 22.07.2026 09:00
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library — thehackernews.com — 22.07.2026 09:00