Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
    Cryptocurrency

    Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

    December 16, 20253 Mins Read


    Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

    Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

    The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

    Cybersecurity

    “It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

    The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

    Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

    “All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

    Cybersecurity

    Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

    The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

    “Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Prediction: This Cryptocurrency Could Soar 257% in 2026

    Cryptocurrency

    Analyzing Cryptocurrency Exchanges by Volume: A 2026 Guide

    Cryptocurrency

    AB Xelerate invests in Ubyx to strengthen global digital money connectivity

    Cryptocurrency

    RTGS, ISO 20022 and digital currencies: Why cross-border payments are heating up: By Rachel Greener

    Cryptocurrency

    As crypto industry expands, U.S. slashes office examining dirty money safeguards of cryptocurrency exchanges

    Cryptocurrency

    Cryptocurrency Fuels Human Trafficking, Child Abuse, and Online Scams, Report Finds

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Cryptocurrency

    Guide to Secure Digital Storage – The Shib Daily

    Commodities

    L’avenir du site d’American Iron & Metal à Moncton « en cours d’examen »

    Precious Metal

    Gold price today: Precious metal declines 2% from all-time high on profit booking; silver drops 3%

    Editors Picks

    Latest Economy News Today on August 19, 2024 Live Updates: Exports of key commodities fall in April-July amid rising trade deficit

    August 19, 2024

    Fête de la Musique 2025 à Évry-Courcouronnes (91) : pop urbaine, flamenco et métal arabo-andalou

    May 28, 2025

    Gold, copper and oil prices fall as stock market contagion spreads

    August 5, 2024

    Microsoft and Meta fuel $648 billion rally in AI stocks as investments pay off

    August 3, 2025
    What's Hot

    AIC warns farmers: Order fertiliser early or risk 2026 shortage

    October 2, 2025

    Vail Williams welcomes Oxford’s property community

    July 12, 2024

    A Developer and Sibling Real Estate Agents Resort to Generative AI to Sell $70 Million California Mansion

    December 31, 2025
    Our Picks

    Le Ghana veut prolonger la durée de vie de la mine d’or Damang avec Gold Fields

    April 24, 2025

    Revealed! 3 of my favourite FTSE 100 income stocks right now

    December 12, 2025

    Stock Market Today Highlights: Sensex ends 500 points lower, Nifty below 26,900; Axis, Reliance top drags

    December 15, 2025
    Weekly Top

    Tides of tax drive high earners to offshore bonds

    February 20, 2026

    Full Metal Jackie’s Heavy Metal Life

    February 20, 2026

    It’s now easier to install MGSHDFix for Metal Gear games on Linux / Steam Deck

    February 20, 2026
    Editor's Pick

    McPhy Energy : Mise à disposition du rapport annuel 2024

    April 25, 2025

    Picton Property annonce une augmentation de 2,7 % de son dividende

    May 5, 2025

    Why Digital Currency Group Is Suing Its Own Subsidiary Over $1.1 Billion Loan

    August 15, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.