Feeds.Feedburner
NuGet Typosquatting Attack Rigging Digitain Game Results
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A malicious NuGet package named 'Newtonsoftt.Json.Net' was discovered, targeting the Digitain betting platform by rigging game results. The package, which mimicked the legitimate Newtonsoft.Json library, was downloaded around 1,200 times before being removed. It specifically affected systems running Digitain's FG-Crash betting game, introducing randomized delays to avoid detection while exfiltrating altered game outcomes to an attacker-controlled server. The malware's progression included increasing obfuscation and sophisticated rigging strategies. Digitain has acknowledged the issue and implemented corrective measures. Developers are advised to remove the package and block the command and control (C2) address. This incident marks a notable evolution in supply chain attacks, focusing on targeted manipulation rather than broad data theft.
Key Points: • The typosquatted package 'Newtonsoftt.Json.Net' was downloaded approximately 1,200 times. • The malware specifically targeted Digitain's FG-Crash betting game, rigging results and exfiltrating data. • Developers are urged to remove the malicious package and block the associated C2 address.