Newtonsoftt.Json.Net trojanized fork rigs Digitain FG-Crash results
Malware Activity
Summary
Hide ▲
Show ▼
The Newtonsoftt.Json.Net package was found delivering a trojanized fork that can rig Digitain FG-Crash results and exfiltrate them, turning a routine library install into a targeted integrity attack. The package masquerades as Newtonsoft.Json for non-targets, but its malicious path only activates when the host reaches the FG-Crash backend method. The malicious versions span 11.0.4 through 11.0.11, published between August 13 and October 10, 2025. The payload sends rigged round results to 185.126.237[.]64:5341 with X-Seq-ApiKey: theperfectheist2025.
Related Happenings
Lazarus Group graphalgo recruitment-themed package campaign
Campaign
H score38
First: 12.02.2026 18:55
Last: 12.02.2026 18:55
Sources 1
About this happening:
The North Korea-linked Lazarus Group is running graphalgo, an active fake recruitment-themed package campaign that is targeting developers through npm and PyPI...
Lazarus Group graphalgo recruitment-themed package campaign
CampaignAbout this happening: The North Korea-linked Lazarus Group is running graphalgo, an active fake recruitment-themed package campaign that is targeting developers through npm and PyPI...
Tracer.Fody.NLog malicious NuGet wallet stealer
Malware Activity
H score30
First: 16.12.2025 17:39
Last: 16.12.2025 17:39
Sources 1
About this happening:
Tracer.Fody.NLog is a malicious NuGet package that steals Stratis wallet data and passwords from .NET projects, creating a supply-chain risk for developers and cryptoc...
Tracer.Fody.NLog malicious NuGet wallet stealer
Malware ActivityAbout this happening: Tracer.Fody.NLog is a malicious NuGet package that steals Stratis wallet data and passwords from .NET projects, creating a supply-chain risk for developers and cryptoc...
Timeline
-
22.07.2026 09:00 2 articles · 2h ago
NuGet typosquat Newtonsoftt.Json.Net targets Digitain's FG-Crash backend
Initial DisclosureA NuGet package named Newtonsoftt.Json.Net masquerades as Newtonsoft.Json and contains a trojanized fork that targets Digitain's FG-Crash crash-game backend. The payload only activates when JsonConvert.DefaultSettings is assigned, introduces a randomized delay to evade detection, and on targeted systems exfiltrates rigged round results to 185.126.237[.]64:5341 while using X-Seq-ApiKey: theperfectheist2025. The package was published in seven versions, 11.0.4 through 11.0.11, downloaded about 1,200 times, and its metadata leaked an internal Digitain repository URL seven times, suggesting access to FG-Crash source code. Digitain has said it was aware of the issue and had taken steps to resolve it.
Show sources
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library — thehackernews.com — 22.07.2026 09:00
- Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library — thehackernews.com — 22.07.2026 09:00