Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 – PA Media
  • Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 | Corporate – EQS News
  • Stella’s Art Gallery in Willoughby hosting a pair of shows
  • The National Gallery’s £750m new wing has reignited London’s art turf war
  • Fraud Victims who invested in the fraudulent cryptocurrency OneCoin between 2014 and 2019 and experienced a net loss may be eligible to receive compensation through the Department of Justice's petition for remission process – The Manila Times
  • OpenAI Acquires Hiro Finance to Boost AI Financial Planning Tools
  • I took a finance course run by millionaires
  • Yahoo Finance – Welcome to the future of finance
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Cryptocurrency

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

December 16, 20253 Mins Read


Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

Cybersecurity

“It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

“All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

Cybersecurity

Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

“Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Fraud Victims who invested in the fraudulent cryptocurrency OneCoin between 2014 and 2019 and experienced a net loss may be eligible to receive compensation through the Department of Justice's petition for remission process – The Manila Times

April 14, 2026 Cryptocurrency

EQS-News: Fraud Victims who invested in the fraudulent cryptocurrency OneCoin between 2014 and 2019 and experienced a net loss may be eligible to receive compensation through the Department of Justice's petition for remission process – boerse.de – boerse.de

April 13, 2026 Cryptocurrency

Fraud Victims who invested in the fraudulent cryptocurrency OneCoin between 2014 and 2019 and experienced a net loss may be eligible to receive compensation through the Department of Justice's petition for remission process – TradingView — Track All Markets

April 13, 2026 Cryptocurrency

FBI Warns Older Americans As Crypto Scams Wipe Out $11.4 Billion In 2025 — Tips To Protect Your Life Savings

April 13, 2026 Cryptocurrency

Is Bitcoin the Safest Cryptocurrency to Own for the Long Term?

April 13, 2026 Cryptocurrency

6 Best Cryptocurrency Platforms for Passive Income (2026)

April 13, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 – PA Media

April 14, 2026 Investments 1 Min Read

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate…

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 | Corporate – EQS News

April 14, 2026

Stella’s Art Gallery in Willoughby hosting a pair of shows

April 14, 2026

The National Gallery’s £750m new wing has reignited London’s art turf war

April 14, 2026
Our Picks

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 – PA Media

April 14, 2026

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 | Corporate – EQS News

April 14, 2026

Stella’s Art Gallery in Willoughby hosting a pair of shows

April 14, 2026

The National Gallery’s £750m new wing has reignited London’s art turf war

April 14, 2026
Our Picks

FBI Warns Older Americans As Crypto Scams Wipe Out $11.4 Billion In 2025 — Tips To Protect Your Life Savings

April 13, 2026

The Secretary for Economy and Finance, Mr Tai Kin Ip, attends the opening ceremony of the 2026 regulatory training programme regarding international modern financial regulatory challenges and responses, held by the “Association of Lusophone Insurance – 澳門特別行政區政府入口網站

April 13, 2026

‘An open letter to the nation’: National Gallery of Art reckons with America at 250 | Art

April 13, 2026
Latest updates

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 – PA Media

April 14, 2026

Vesper Next Generation Infrastructure Fund I, and co-investment initiatives, reach final close surpassing in aggregate EUR 1bn of total AuM, the most successful debut mid-market infrastructure funds since 2023 | Corporate – EQS News

April 14, 2026

Stella’s Art Gallery in Willoughby hosting a pair of shows

April 14, 2026
Weekly Updates

Mitchell-Innes & Nash Gallery Is Closing to Become an Art Advisory

June 24, 2024

How Gen Z Can Choose the Right Financial Advisor Their Needs

August 17, 2024

Cryptocurrency firms plan for survival, move overseas as RBI steps up heat

April 2, 2026
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.