Newtonsoftt.Json.Net : .NET ライブラリのトロイの木馬化されたフォークで、スポーツ賭博を不正に操作する

サイバーセキュリティ 3 h agoブックマークに追加

Newtonsoftt.Json.Net : .NET ライブラリのトロイの木馬化されたフォークで、スポーツ賭博を不正に操作する
Illustration : Momiji Shirogane

NuGet パッケージが Newtonsoft.Json に非常に似ており、実際に動作するライブラリの中に、Digitain のライブパリ結果を改ざんするためのコードが隠されています。

Faits

According to The Hacker News (July 22, 2026), researchers discovered a typosquat on NuGet named « Newtonsoftt.Json.Net » - two "t"s - that impersonates the famous library Newtonsoft.Json. Seven versions have been published on the registry. This is not a classic info-stealer: it's a trojanized fork that specifically targets live sports betting on Digitain.

Analyse

Two points stand out.

The NuGet typosquat remains an open surface. The difference of one character between Newtonsoft.Json (the real one, ~4 billion historical downloads according to nuget.org) and Newtonsoftt.Json.Net is enough to trap any unfortunate copy-paste in a CSPROJ, a CI build script, or a StackOverflow doc - not to mention LLMs that regularly hallucinate similar package names.

The payload is atypical. The attacker does not sell credit cards nor does he set up a general RAT. He targets a specific platform (Digitain, an iGaming software provider used by many bookmakers) and a specific class of fraud (rigging live results). This is finalized supply chain: the developer who integrates the lib is a vector towards a specific production environment, not a target in itself.

Que faire

À faire maintenant :

  • Auditer vos dépendances NuGet à la recherche de Newtonsoftt.Json.Net (grep sur les fichiers .csproj, packages.lock.json, artefacts CI).
  • Si présent : retirer, recompiler, faire tourner un scan antimalware sur les hôtes de build et les serveurs qui ont exécuté le binaire.
  • Épingler la vraie Newtonsoft.Json (Author: James Newton-King, ID exact) dans un NuGet.config restrictif avec packageSourceMapping.
  • Activer la vérification de signature des packages et, si possible, restreindre les sources NuGet à un miroir interne validé.

À retenir

Supply-chain typosquatting is no longer just about "stealing npm tokens". A package can be a targeted tool against a sector (here iGaming) - vigilance over dependency names has become basic hygiene, not a luxury.

リソース

本記事は人工知能により作成され、人間の編集管理のもとで校閲されています。

編集部について
この記事は役に立ちましたか?

23 人がこの記事を評価しました

いいね
K
Kenji Araiサイバーセキュリティ専門家
Expert in cybersecurity, meticulous observer, never alarmist, always actionable.
シェア:
LIVERadio Geek Kitsune
タップして再生、みんなで同じ音を
0··
// 番組表
// 全ステーション
// 楽曲を共有する →
テーマ
探索
インフォメーション