Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • Record Year for Entries as Finalists Announced for Finance Awards Wales 2026
  • Black Country art gallery set to reopen free library featuring thousands of books and resources
  • Finance Minister John O’Dowd says £17m heating oil support ‘extremely disappointing’ | UTV
  • Crypto Market Daily Movements | Cryptocurrency market surges, with Bitcoin rising to $74,000; Michael Saylor releases another Bitcoin Tracker update, with potential disclosure of additional purchase data expected this week. – 富途牛牛
  • The rise and fall of ‘buy-one, give-one’ art sales – The Art Newspaper
  • National Gallery of Art curator goes viral on social media for using Gen Z slang
  • The Scary Guy’s art gallery opens its doors for a Wigan festival exhibition
  • US-Iran war: Major cryptocurrency conference Token2049 Dubai postponed to 2027 as Middle East conflict continues
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Cryptocurrency

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

December 16, 20253 Mins Read


Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

Cybersecurity

“It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

“All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

Cybersecurity

Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

“Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto Market Daily Movements | Cryptocurrency market surges, with Bitcoin rising to $74,000; Michael Saylor releases another Bitcoin Tracker update, with potential disclosure of additional purchase data expected this week. – 富途牛牛

March 16, 2026 Cryptocurrency

US-Iran war: Major cryptocurrency conference Token2049 Dubai postponed to 2027 as Middle East conflict continues

March 14, 2026 Cryptocurrency

United States Cryptocurrency Market Forecast and Company Analysis Report 2025-2033 Featuring AMD, Binance, Bit fury, Bit Go, Bit Main Technologies, Intel, NVIDIA, Ripple, Xapo, Xilinx – Yahoo Finance Singapore

March 13, 2026 Cryptocurrency

XRP vs. Cardano (ADA): Which Cryptocurrency Deserves Your Investment in 2026?

March 13, 2026 Cryptocurrency

Pi Day Update: What’s Happening With The Controversial Cryptocurrency?

March 12, 2026 Cryptocurrency

Crypto Market Daily Update | The cryptocurrency market experienced downward volatility, with Bitcoin falling below $70,000; the U.S. SEC and CFTC signed a Memorandum of Understanding, pledging to collaborate on formulating crypto policies and promotin – 富途牛牛

March 12, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Record Year for Entries as Finalists Announced for Finance Awards Wales 2026

March 16, 2026 Finance 4 Mins Read

The Finance Awards Wales 2026 has officially revealed this year’s finalists, recognising the outstanding achievements…

Black Country art gallery set to reopen free library featuring thousands of books and resources

March 16, 2026

Finance Minister John O’Dowd says £17m heating oil support ‘extremely disappointing’ | UTV

March 16, 2026

Crypto Market Daily Movements | Cryptocurrency market surges, with Bitcoin rising to $74,000; Michael Saylor releases another Bitcoin Tracker update, with potential disclosure of additional purchase data expected this week. – 富途牛牛

March 16, 2026
Our Picks

Record Year for Entries as Finalists Announced for Finance Awards Wales 2026

March 16, 2026

Black Country art gallery set to reopen free library featuring thousands of books and resources

March 16, 2026

Finance Minister John O’Dowd says £17m heating oil support ‘extremely disappointing’ | UTV

March 16, 2026

Crypto Market Daily Movements | Cryptocurrency market surges, with Bitcoin rising to $74,000; Michael Saylor releases another Bitcoin Tracker update, with potential disclosure of additional purchase data expected this week. – 富途牛牛

March 16, 2026
Our Picks

UK ‘home bias’ drives surge in Isa millionaires, say investment platforms

March 13, 2026

Major Partnerships and Investment Collaborations emerged from the Sustainable Markets Initiative's annual CEO Summit at Hampton Court Palace, as Global Business Leaders accelerated action on the Sustainable Transition – Yahoo Finance Singapore

March 13, 2026

United States Cryptocurrency Market Forecast and Company Analysis Report 2025-2033 Featuring AMD, Binance, Bit fury, Bit Go, Bit Main Technologies, Intel, NVIDIA, Ripple, Xapo, Xilinx – Yahoo Finance Singapore

March 13, 2026
Latest updates

Record Year for Entries as Finalists Announced for Finance Awards Wales 2026

March 16, 2026

Black Country art gallery set to reopen free library featuring thousands of books and resources

March 16, 2026

Finance Minister John O’Dowd says £17m heating oil support ‘extremely disappointing’ | UTV

March 16, 2026
Weekly Updates

Khamzat Chimaev Faces Cryptocurrency Fraud Allegations MMAnytt.com

July 6, 2024

K-12 Wicasset Public Schools Student Art Show at Maine Art Gallery, Wiscasset, ME

April 14, 2024

A Look at His Most Expensive Investments in Art

October 15, 2025
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.