By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Trojanized Newtonsoft.Json Fork Rigged Game Results

Cybersecurity researchers identified a malicious NuGet package, "Newtonsoftt.Json.Net," which is a trojanized fork of the popular Newtonsoft.Json library. This package was designed not to steal information, but to actively rig live game results on the Digitain platform. Seven versions of this compromised package were published to the NuGet registry, posing a significant threat to the integrity of online gaming.
The discovered malware differs from typical information-stealing threats often found on package registries. Instead of exfiltrating sensitive data, its primary function is to alter the outcomes of games played through Digitain's services. This sophisticated attack vector targets the trust and fairness expected in online gaming environments, potentially leading to significant financial losses for players and reputational damage for the platform.
The attackers employed a typosquatting technique, creating a package name that closely resembles the legitimate "Newtonsoft.Json" library. This tactic aims to trick developers into unknowingly downloading and integrating the malicious code into their projects. Once incorporated, the trojanized code can execute its game-rigging functions, compromising the integrity of the gaming ecosystem.
Digitain, the platform targeted by this attack, is a prominent provider of white-label solutions for the iGaming industry. The successful deployment of such malware could have far-reaching consequences, impacting numerous operators and their player bases who rely on Digitain's services. The discovery highlights the ongoing challenges in securing software supply chains and the evolving tactics of cybercriminals.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.