Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
    Cryptocurrency

    Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

    December 16, 20253 Mins Read


    Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

    Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

    The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

    Cybersecurity

    “It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

    The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

    Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

    “All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

    Cybersecurity

    Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

    The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

    “Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Prediction: This Cryptocurrency Could Soar 257% in 2026

    Cryptocurrency

    Analyzing Cryptocurrency Exchanges by Volume: A 2026 Guide

    Cryptocurrency

    AB Xelerate invests in Ubyx to strengthen global digital money connectivity

    Cryptocurrency

    RTGS, ISO 20022 and digital currencies: Why cross-border payments are heating up: By Rachel Greener

    Cryptocurrency

    As crypto industry expands, U.S. slashes office examining dirty money safeguards of cryptocurrency exchanges

    Cryptocurrency

    Cryptocurrency Fuels Human Trafficking, Child Abuse, and Online Scams, Report Finds

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    New Zealand Energy Corp. Announces Management and Board Changes

    Fintech

    Israeli Fintech expands into South Korea through KB securities collaboration

    Cryptocurrency

    Kazakhstan uses programmable CBDC to pay for railway to China

    Editors Picks

    MOFA receives agricultural products, tractor for Farmers Day

    December 1, 2025

    South America Commercial Greenhouse Market Forecasts 2024:

    July 22, 2024

    Sortie en bateau pour voir des dauphins : comment bien en profiter ?

    April 21, 2025

    BTL property investment bounces back following last year’s Budget

    August 28, 2025
    What's Hot

    Aera Technology dévoilera l’avenir de l’entreprise autonome à l’évènement AeraHUB 2025 à Londres

    June 3, 2025

    5 Excellent Retirement Calculators (And All Are Free)

    July 12, 2015

    Dow, S&P 500, Nasdaq surge after US jobs report

    June 6, 2025
    Our Picks

    Indian Hotels to Dalmia Bharat Sugar: 3 stocks to trade ex-dividend today

    June 29, 2025

    Crypto, fintech Groups Urge CFPB to Defend Open Banking Rule

    October 21, 2025

    La solution patrimoniale signée La Patrimoniale, à découvrir sur financieres.com

    May 22, 2025
    Weekly Top

    Full Metal Jackie’s Heavy Metal Life

    February 20, 2026

    It’s now easier to install MGSHDFix for Metal Gear games on Linux / Steam Deck

    February 20, 2026

    Ofgem shares 10 easy ways for Brits to slash their energy bills

    February 20, 2026
    Editor's Pick

    Ukrainian agricultural exports double in July despite intensified…

    August 23, 2024

    Global Fintech Fest (GFF): Soon, you will be able to buy foreign currency via UPI using glasses?

    October 7, 2025

    Technology Breaking Boundaries – How the Fintech Sector Is Benefiting

    September 30, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.