Security News

Cybersecurity news aggregator

HIGH Vulnerabilities SC Media

NuGet typosquat targets Digitain game results

A sophisticated NuGet typosquat package named "Newtonsoftt.Json.Net" targeted the Digitain betting platform, masquerading as the legitimate Newtonsoft.Json library. The malicious package, downloaded roughly 1,200 times across seven versions published between August 13 and October 10, 2025, specifically rigged results in Digitain's FG-Crash game and exfiltrated data to a command-and-control server at 185.126.237.64:5341. Developers are advised to remove this package, block the C2 address, and pin dependencies to a known-good version of the legitimate library.
Read Full Article →

Supply chain NuGet typosquat targets Digitain game results July 22, 2026 Share By SC Staff A sophisticated NuGet typosquat package has been discovered by JFrog that deviates from typical information-stealing malware by actively rigging live game results on the Digitain platform. The malicious package, named "Newtonsoftt.Json.Net," masqueraded as a legitimate library and was downloaded approximately 1,200 times before being unlisted by its owner. This discovery highlights a new tactic in supply chain attacks, with further coverage provided by The Hacker News. The trojanized package, which mimicked the popular Newtonsoft.Json library, published seven versions between August 13 and October 10, 2025. While appearing to function normally for most users, it specifically targeted Digitain's FG-Crash betting game. Upon initialization of JsonConvert.DefaultSettings, a randomized delay was introduced to evade detection before rigging round results and exfiltrating them to an attacker-controlled server at 185.126.237.64:5341. The progression of the malware across three generations showed increasing obfuscation, rigging strategies, and exfiltration stabilization. Notably, the package metadata leaked an internal Digitain repository URL, suggesting the attacker had prior access to the source code. The attack's effectiveness lies in its targeted nature; only systems running Digitain's specific backend methods were affected, leaving other consumers unaware of the malware. Developers are advised to remove the package, block the C2 address, and pin to a known-good version. Digitain has acknowledged the issue and stated it has taken corrective actions. Source: The Hacker News SC Staff Related Supply chain SleeperGem attack targets Ruby ecosystem with malicious gems SC Staff July 20, 2026 The SleeperGem attack utilizes three malicious Ruby gems: git_credential_manager, Dendreo, and fastlane-plugin-run_tests_firebase_testlab. Supply chain New npm malware cluster targets Vite ecosystem SC Staff July 20, 2026 The ViteVenom campaign, attributed to the threat actor SuccessKey, builds upon the tactics seen in the earlier ChainVeil attack. Supply chain Jscrambler npm package version 8.14.0 contained a malicious infostealer SC Staff July 13, 2026 The jscrambler supply chain attack involved a malicious preinstall hook within version 8.14.0 of the npm package. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article