Feeds.Feedburner
NuGet Typosquatting Attack Rigging Digitain Game Results
Article Content
A malicious NuGet package named 'Newtonsoftt.Json.Net' was discovered, targeting the Digitain betting platform by rigging game results. The package, which mimicked the legitimate Newtonsoft.Json library, was downloaded around 1,200 times before being removed. It specifically affected systems running Digitain's FG-Crash betting game, introducing randomized delays to avoid detection while exfiltrating altered game outcomes to an attacker-controlled server. The malware's progression included increasing obfuscation and sophisticated rigging strategies. Digitain has acknowledged the issue and implemented corrective measures. Developers are advised to remove the package and block the command and control (C2) address. This incident marks a notable evolution in supply chain attacks, focusing on targeted manipulation rather than broad data theft.
Key Points: • The typosquatted package 'Newtonsoftt.Json.Net' was downloaded approximately 1,200 times. • The malware specifically targeted Digitain's FG-Crash betting game, rigging results and exfiltrating data. • Developers are urged to remove the malicious package and block the associated C2 address.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.