Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
    Cryptocurrency

    Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

    December 16, 20253 Mins Read


    Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

    Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

    The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

    Cybersecurity

    “It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

    The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

    Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

    “All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

    Cybersecurity

    Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

    The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

    “Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    What new cryptocurrency regulations mean for investors

    Cryptocurrency

    Better Cryptocurrency to Buy Now With $4,000: XRP (Ripple) vs. Dogecoin

    Cryptocurrency

    Bhutan pledges US$1bil cryptocurrency for ‘mindfulness’ city

    Cryptocurrency

    How cryptocurrency is changing politics

    Cryptocurrency

    Essentials for Starting to Accept Cryptocurrency Payments on Your Website

    Cryptocurrency

    Bitcoin stumbles below $86,000 as cryptocurrency maintains downward trajectory

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Au cœur du tiers-lieu ZAÏ, la métallurgie rallume l’espoir et les projets collectifs dans ce village de l’Ariège

    Investments

    Info Edge start-up investments yield 36% return in FY25

    Fintech

    Temasek-backed fintech lender Kissht files for Rs 1,000 crore IPO to augment NBFC subsidiary’s capital base – Start Ups News

    Editors Picks

    Imports, climate change threaten agricultural sector despite record production

    June 19, 2025

    NV Gold Announces Amended Triple T Property Lease Agreement

    July 8, 2025

    Stock Market Closing: Sensex Rises 111 Points, Nifty At 26,216; IT, Pvt Bank Shares Gain

    November 27, 2025

    Commodity farmers can apply for emergency economic relief

    March 25, 2025
    What's Hot

    « Dans 5 ans, l’Afrique francophone pèsera très lourd dans la tech africaine » 

    June 22, 2025

    Russia To Officially Use Cryptocurrency For Trade Settlements

    August 27, 2024

    Popular used car dealership behind YouTube channel Shifting Metal to CLOSE – Car Dealer Magazine

    August 10, 2025
    Our Picks

    UBS tells investors to buy silver amid Trump tariff turmoil

    April 9, 2025

    Le Métal Pless amorce ses séries avec une victoire 

    February 28, 2025

    One Big Beautiful Bill Act: Agricultural Provisions | Market Intel

    June 4, 2025
    Weekly Top

    London property prices fall at fastest pace in nearly 2 years

    December 17, 2025

    China poses major risk to Europe’s energy grids, top NATO official warns – POLITICO

    December 17, 2025

    Copper’s next shortage is structural, not hype: analyst

    December 17, 2025
    Editor's Pick

    US Treasury Begins $50,000,000,000 Liquidity Injection As Trillion-Dollar Bond Market Witnesses Weak Demand

    August 10, 2024

    Cyclisme sur route – Amstel Gold Race femmes 2025 : Pauline Ferrand-Prévot peut-elle remporter une deuxième victoire de suite ?

    April 17, 2025

    Simon Property Group : baisse du FFO au premier trimestre, hausse du chiffre d’affaires ; perspectives pour 2025 réaffirmées

    May 12, 2025
    © 2025 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.