Close Menu
Invest Intellect
    Facebook X (Twitter) Instagram
    Invest Intellect
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Commodities
    • Cryptocurrency
    • Fintech
    • Investments
    • Precious Metal
    • Property
    • Stock Market
    Invest Intellect
    Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
    Cryptocurrency

    Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

    December 16, 20253 Mins Read


    Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

    Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

    The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

    Cybersecurity

    “It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

    The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

    Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

    “All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

    Cybersecurity

    Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

    The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

    “Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    BBC Learning English – 6 Minute English / Bitcoin: digital crypto-currency

    Cryptocurrency

    Fintech Stock SoFi Technologies Just Proved That the Ultimate Cryptocurrency Has a Clear Use Case

    Cryptocurrency

    Facing a global threat, Tunisia escalates fight against digital money laundering, new study finds

    Cryptocurrency

    India takes lead as BRICS eyes digital payment system to bypass dollar. All about the BRICS payment system

    Cryptocurrency

    Will Budget 2026 provide clarity on cryptocurrency taxation, simplify compliance?

    Cryptocurrency

    PayPal and NCA Survey Shows Rising Merchant Adoption of Cryptocurrency Payments

    Cryptocurrency
    Leave A Reply Cancel Reply

    Top Picks
    Commodities

    Shifting Agricultural Exports Represent Dynamic Morocco-EU Relations

    Cryptocurrency

    Understanding Bitcoin Technology: How It Works & Why It Matters

    Cryptocurrency

    Cryptocurrency Live News & Updates : IRS Crypto Warning Letters Surge by 758%

    Editors Picks

    Trump metal tariffs widening to include furniture, knives, ACs

    August 19, 2025

    Le Métal Pless savoure une huitième victoire successive

    January 26, 2025

    Harvesting amid the bombs in Gaza: ‘Olive trees are like us: resilient and with deep roots in this land’ | International

    October 29, 2024

    Foreign investors snap up Japanese government bonds as yields surge

    November 20, 2025
    What's Hot

    BlackRock: Investors Will Back Energy Over Big Tech in 2026

    January 15, 2026

    With “electro-agriculture,” plants can produc

    October 23, 2024

    Experian Assistant Wins 2025 FinTech Breakthrough Award for Analytics Innovation

    March 20, 2025
    Our Picks

    Comment la prévision des tempêtes et des canicules fait des bonds grâce à l’IA

    May 21, 2025

    Gen Z turns back on property to build wealth, Revolut survey claims – The Irish Times

    September 16, 2025

    Alpha Copper Corp. annonce des changements de secrétaire général -Le 16 janvier 2025 à 00:39

    January 15, 2025
    Weekly Top

    Accounting and Reporting Techniques Fintech Firms Use in 2026

    January 30, 2026

    Fintech bytes: Docupace touts 200,000-hour windfall for PreciseFP and Hubly users in 2025

    January 30, 2026

    Why Your Retirement Age Doesn’t Matter (But This Number Does)

    January 30, 2026
    Editor's Pick

    NextStar Energy expands production

    November 3, 2025

    China Keeps Adding Gold to Reserves as Challenges Stack Up

    May 7, 2025

    Mac Copper Outlook 2025 For CSA Copper Mine Production Of 43,000 – 48,000 Tones (en anglais seulement) -Le 24 février 2025 à 12:38

    February 24, 2025
    © 2026 Invest Intellect
    • Contact us
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.