Find notable cyber news and cases, enriched with sources, timelines, and signals.

Newtonsoftt.Json.Net trojanized fork rigs Digitain FG-Crash results

Malware Activity
First reported
Last updated
Happening score
H score 4
1 unique sources, 1 articles

Summary

Hide ▲

The Newtonsoftt.Json.Net package was found delivering a trojanized fork that can rig Digitain FG-Crash results and exfiltrate them, turning a routine library install into a targeted integrity attack. The package masquerades as Newtonsoft.Json for non-targets, but its malicious path only activates when the host reaches the FG-Crash backend method. The malicious versions span 11.0.4 through 11.0.11, published between August 13 and October 10, 2025. The payload sends rigged round results to 185.126.237[.]64:5341 with X-Seq-ApiKey: theperfectheist2025.

Related Happenings

Lazarus Group graphalgo recruitment-themed package campaign

Campaign
H score38 First: 12.02.2026 18:55 Last: 12.02.2026 18:55 Sources 1

About this happening: The North Korea-linked Lazarus Group is running graphalgo, an active fake recruitment-themed package campaign that is targeting developers through npm and PyPI...

BeaverTail and InvisibleFerret backdoor delivery via malicious VS Code task abuse

Malware Activity
H score39 First: 20.01.2026 20:41 Last: 20.01.2026 20:41 Sources 1

About this happening: North Korean threat actors tied to Contagious Interview are using the PolinRider malware activity to seed malicious packages and loaders across developer ecosystems. T...

Latest development: 22.04.2026 17:48

North Korean actor Void Dokkaebi, aka Famous Chollima, is turning the Contagious Interview fake-job lure into a self-propagating software supply-chain infection that abuses compromised developer repositories, malicious VS Code tasks, and injected code to spread malware and steal credentials. The campaign targets developers seeking work, can hide a poisoned .vscode folder in committed code, and Trend Micro said it found more than 750 infected code repositories, more than 500 malicious VS Code task configurations, and 101 commit-tampering instances in March.

Tracer.Fody.NLog malicious NuGet wallet stealer

Malware Activity
H score30 First: 16.12.2025 17:39 Last: 16.12.2025 17:39 Sources 1

About this happening: Tracer.Fody.NLog is a malicious NuGet package that steals Stratis wallet data and passwords from .NET projects, creating a supply-chain risk for developers and cryptoc...

Timeline

  1. 22.07.2026 09:00 2 articles · 13d ago

    NuGet typosquat Newtonsoftt.Json.Net targets Digitain's FG-Crash backend

    Initial Disclosure

    A NuGet package named Newtonsoftt.Json.Net masquerades as Newtonsoft.Json and contains a trojanized fork that targets Digitain's FG-Crash crash-game backend. The payload only activates when JsonConvert.DefaultSettings is assigned, introduces a randomized delay to evade detection, and on targeted systems exfiltrates rigged round results to 185.126.237[.]64:5341 while using X-Seq-ApiKey: theperfectheist2025. The package was published in seven versions, 11.0.4 through 11.0.11, downloaded about 1,200 times, and its metadata leaked an internal Digitain repository URL seven times, suggesting access to FG-Crash source code. Digitain has said it was aware of the issue and had taken steps to resolve it.

    Show sources