- JFrog found Newtonsoftt.Json.Net, a Trojan NuGet package that mimics the popular Newtonsoft.Json library
- The malware specifically targeted Digitain’s crash-game backend, rigging results with insider knowledge of its codebase
- The issue was quickly resolved, but the attackers remain unidentified
Security researchers JFrog have discovered a unique Trojan targeting one particular company while letting everyone else infected walk away unscathed.
The Trojan, named Newtonsoftt.Json.Net, is a typosquatted NuGet package variant of the very popular JSON library called Newtonsoft.Json. The legitimate package is one of the most used code libraries in the .NET programming world, which is necessary for almost every existing project. It is a small piece of software that helps .NET applications read, understand and exchange data between different systems.
According to JFrog, someone released an almost identical package, copied the real author’s name, license, and made it work as intended. For almost everyone who installed it, it worked perfectly normally. For developers working on Digitain’s crash-game backend, however, it’s a completely different story.
Rigging the games
Digitain is an Armenian software company that provides online sports betting and gaming software platforms to gambling companies worldwide.
On the infected machine running Digitain’s real crash-game code, the malware swaps in a rich number instead of a fair one, using a formula based on the date and time.
What this means is that the results of the gambling game are rigged so that the attackers can know in advance which rounds are being manipulated and place their bets accordingly.
The malware also creates a private confirmation channel to report back for each rigged round, allowing the attackers to know whether the cheat still works or not.
JFrog did not identify the attackers, but they stressed that it was most likely an insider.
Apparently, only someone with inside knowledge of Digitain’s codebase (for example, a current or former employee or a contractor) could have built such an exploit, as it required knowledge of the exact internal function name inside Digitain’s game engine that determines the outcome of the crash game.
The researchers contacted Digitain on July 7, 2026 and were informed two days later that the issue had already been escalated to the team and in the meantime fixed.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



