- JFrog found Newtonsoftt.Json.Net, a Trojan NuGet package that imitates the popular Newtonsoft.Json library
- The malware specifically targeted the backend of Digitain’s crash-game, manipulating the results with internal knowledge of its code base.
- The problem was quickly fixed but the attackers remain unidentified
JFrog security researchers have discovered a unique Trojan that targets a specific company, while allowing all other infected people to escape unscathed.
The Trojan, named Newtonsoftt.Json.Net, is a typo-pocked NuGet package variant of the popular JSON library called Newtonsoft.Json. The legitimate package is one of the most used code libraries in the world of .NET programming, required for almost all existing projects. It is a small software that helps .NET applications read, understand and exchange data between different systems.
According to JFrog, someone published a nearly identical package, copied the real author’s name and license, and made it work as intended. For almost anyone who installed it, it worked completely normal. However, for the developers working on the backend of Digitain’s crash game, it’s a completely different story.
Fixing the games
Digitain is an Armenian software company that provides online sports betting and gaming software platforms to gaming companies around the world.
On the infected machine running the actual Digitain game code, the malware exchanges a manipulated number instead of a fair one, using a formula based on date and time.
What this means is that the results of the betting game are rigged, allowing attackers to know in advance which rounds are rigged and place their bets accordingly.
The malware also sets up a private confirmation channel to report each manipulated round, allowing attackers to know whether the cheat code still works or not.
JFrog did not identify the attackers, but they did emphasize that they were most likely an insider.
Apparently, only someone with inside knowledge of Digitain’s codebase (e.g., a current or former employee, or contractor) could have created such an exploit, as it required knowledge of the exact name of the internal function within Digitain’s game engine that decides the outcome of the game.
Researchers contacted Digitain on July 7, 2026 and were notified two days later that the issue had already been escalated to the team and had been fixed in the meantime.
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




