Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library
Summary
A typosquatting attack on the NuGet package registry has been discovered, distributing a malicious fork of the Newtonsoft.Json library. This trojanized library is designed to manipulate live game results for the company Digitain, rather than stealing information.
IFF Assessment
FOE
This discovery represents a new type of malicious activity targeting supply chains to directly interfere with online operations, posing a threat to organizations and their users.
Defender Context
This incident highlights the ongoing risks associated with software supply chain attacks, specifically through package registries like NuGet. Defenders need to be vigilant about validating package sources and versions, as malicious actors are evolving their tactics beyond simple information stealing.