Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Summary

A typosquatting attack on the NuGet package registry has been discovered, distributing a malicious fork of the Newtonsoft.Json library. This trojanized library is designed to manipulate live game results for the company Digitain, rather than stealing information.

IFF Assessment

FOE

This discovery represents a new type of malicious activity targeting supply chains to directly interfere with online operations, posing a threat to organizations and their users.

Defender Context

This incident highlights the ongoing risks associated with software supply chain attacks, specifically through package registries like NuGet. Defenders need to be vigilant about validating package sources and versions, as malicious actors are evolving their tactics beyond simple information stealing.

Read Full Story →