Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates Results via C2 — Threadlinqs Intelligence
As of 2026-07-22, Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates Results via C2 is a high-severity supply chain threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1606 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
A typosquatted NuGet package impersonating Newtonsoft.Json (named Newtonsoftt.Json.Net) shipped seven versions between August-October 2025 with a trojanized JsonConvert.DefaultSettings hook that rigs
JFrog Security Research (analyst Guy Korolevski) discovered and disclosed "Newtonsoftt.Json.Net" (double-t, .Net suffix) — a typosquat of the ubiquitous Newtonsoft.Json library — published to the NuGet Gallery by an unverified account ("MagicalPuff96") across seven versions (11.0.4, 11.0.5, 11.0.7-11.0.11) from August 13 to October 10, 2025, accumulating roughly 1,200 downloads before being unlisted. The package bundles a real, functioning fork of Newtonsoft.Json 13.0.3 (Newtonsoft.Json.net.dll) alongside two malicious components: Newtonsoft.Values.Net.dll (rigging/exfiltration payload) and 0Harmony.dll (the HarmonyLib runtime-patching library). Developers who typo-install the package get working JSON serialization; the trojan activates only when the host application calls the JsonConvert.DefaultSettings property setter, at which point the payload swaps in a custom CamelCasePropertyNamesContractResolver and schedules a delayed Harmony patch (10-minute timer in the final generation) under Harmony instance ID "com.example.harmony", specifically targeting the method Digitain.FG.SharedCrash.GameLogic.SharedCrashRules.GenerateGameResult. This environment-keyed design means the payload is dormant and undetectable on any host that does not expose Digitain's specific FG-Crash backend method, and activation is deliberately delayed past application startup so startup logs appear clean.
The malware evolved across three generations. Generation 1 (v11.0.7, 11.0.8; Dotfuscator-obfuscated, base64 strings visible in the #US heap) used an IL transpiler to rewrite compiled crash-coefficient logic, selecting rigged outcomes from lookup tables indexed by month, day-of-week, and week-of-month, capping manipulation at 27 rounds, with a distinct betting-strategy carve-out for the 22:00 UTC window. Generation 2 (v11.0.4, 11.0.5, 11.0.9; heavy ConfuserEx encryption, reflection-based networking to hide HttpClient usage) added exfiltration of rigged results to 185.126.237.64:5341/api/events/raw, authenticated with header "X-Seq-ApiKey: theperfectheist2025" and deliberately structured to mimic a Seq structured-logging server's ingestion schema so the traffic blends with legitimate application telemetry. Generation 3 (v11.0.10, light ConfuserEx; v11.0.11, completely unobfuscated — apparently an accidental clean build) simplified the rigging to a direct postfix overwrite of the return value, capped at 32 rounds, and stabilized the exfiltration path. No version implements credential theft, host persistence beyond the patched process, or lateral movement — the payload is single-purpose, aimed exclusively at compromising FG-Crash game-outcome integrity and monetizing knowledge of rigged results.
The package's nuspec metadata deliberately (or carelessly) embedded a repository URL pointing to Digitain's internal TFS server, project path BetOnGames/FG-Crash, identically across all seven versions — strong forensic evidence that the threat actor had direct access to Digitain's proprietary FG-Crash source tree, elevating this from a generic typosquat to a targeted, insider-informed supply-chain attack against a single named victim. JFrog tracks detection as XRAY-1019668; JFrog Curation also flags the package. Digitain acknowledged awareness and stated remediation was underway; full exposure scope was undisclosed at time of reporting.
Weaknesses (CWE)
CWE-506, CWE-1357
Target sectors: gambling, igaming, software supply chain, technology
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1587, T1608, T1583, T1195, T1195, T1574, T1036, T1027, T1027, T1620