Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • The Sky’s The Limit: Shaping The UK’s Digital Financial Future – Speech By Sasha Mills, Bank Of England, Executive Director, Financial Market Infrastructure, Given At The Tokenisation Summit – Mondo Visione
  • Lloyds sees annual profits jump 12% in spite of motor finance hit – Yahoo Finance UK
  • Tania Willard wants to take you beyond the art gallery
  • Manappuram Finance Q3 Results: Profit slips, NII remains flat; dividend declared
  • Gloucester’s empty shops to be transformed into art spaces
  • Cryptocurrency Market Trends and Global Forecasts Report 2025-2035: Millennial-Led Participation and the Emergence of Crypto as a Viable Career Path Redefine Financial Sector Perceptions – ResearchAndMarkets.com – Business Wire
  • Japan’s finance ministry isn’t a massive macro hedge fund
  • Crypto Market Daily Movements | The cryptocurrency market has rebounded amid volatility, with Bitcoin nearing the $90,000 mark; according to Bloomberg, Tether has become the largest holder of gold reserves outside sovereign nations and banks, currently – 富途牛牛
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Cryptocurrency

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

December 16, 20253 Mins Read


Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

Cybersecurity

“It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

“All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

Cybersecurity

Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

“Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cryptocurrency Market Trends and Global Forecasts Report 2025-2035: Millennial-Led Participation and the Emergence of Crypto as a Viable Career Path Redefine Financial Sector Perceptions – ResearchAndMarkets.com – Business Wire

January 28, 2026 Cryptocurrency

Crypto Market Daily Movements | The cryptocurrency market has rebounded amid volatility, with Bitcoin nearing the $90,000 mark; according to Bloomberg, Tether has become the largest holder of gold reserves outside sovereign nations and banks, currently – 富途牛牛

January 28, 2026 Cryptocurrency

Will Budget 2026 provide clarity on cryptocurrency taxation, simplify compliance?

January 28, 2026 Cryptocurrency

PayPal and NCA Survey Shows Rising Merchant Adoption of Cryptocurrency Payments

January 28, 2026 Cryptocurrency

Cryptocurrency Leverage Trading Explained: How It Really Works

January 27, 2026 Cryptocurrency

Coinbase adverts banned in UK for suggesting crypto could ease cost of living crisis | Cryptocurrencies

January 27, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

The Sky’s The Limit: Shaping The UK’s Digital Financial Future – Speech By Sasha Mills, Bank Of England, Executive Director, Financial Market Infrastructure, Given At The Tokenisation Summit – Mondo Visione

January 29, 2026 Finance 1 Min Read

The Sky’s The Limit: Shaping The UK’s Digital Financial Future – Speech By Sasha Mills,…

Lloyds sees annual profits jump 12% in spite of motor finance hit – Yahoo Finance UK

January 29, 2026

Tania Willard wants to take you beyond the art gallery

January 29, 2026

Manappuram Finance Q3 Results: Profit slips, NII remains flat; dividend declared

January 29, 2026
Our Picks

The Sky’s The Limit: Shaping The UK’s Digital Financial Future – Speech By Sasha Mills, Bank Of England, Executive Director, Financial Market Infrastructure, Given At The Tokenisation Summit – Mondo Visione

January 29, 2026

Lloyds sees annual profits jump 12% in spite of motor finance hit – Yahoo Finance UK

January 29, 2026

Tania Willard wants to take you beyond the art gallery

January 29, 2026

Manappuram Finance Q3 Results: Profit slips, NII remains flat; dividend declared

January 29, 2026
Our Picks

Cryptocurrency Leverage Trading Explained: How It Really Works

January 27, 2026

Pension funds urged to back alternative investments

January 27, 2026

UK Construction Industry Report 2025: Output to Register an AAGR of 3.2% Between 2026-2029, Supported by Investments in Infrastructure, Data Centers, Housing, and Renewable Energy Projects – ResearchAndMarkets.com – Business Wire

January 27, 2026
Latest updates

The Sky’s The Limit: Shaping The UK’s Digital Financial Future – Speech By Sasha Mills, Bank Of England, Executive Director, Financial Market Infrastructure, Given At The Tokenisation Summit – Mondo Visione

January 29, 2026

Lloyds sees annual profits jump 12% in spite of motor finance hit – Yahoo Finance UK

January 29, 2026

Tania Willard wants to take you beyond the art gallery

January 29, 2026
Weekly Updates

Interim Credit Suisse Review Blasts Finma and SNB, SZ Reports

July 14, 2024

Is Commercial Real Estate a Good Investment?

July 27, 2024

China’s clean energy investments reached $940bn in 2024

February 19, 2025
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.