Close Menu
Finance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Facebook X (Twitter) Instagram
Trending
  • During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov
  • Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK
  • EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations
  • What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate
  • Regulator tells property lender Kingscrown Finance to stop taking on new customers
  • South Asian show at carwright Hall draws new Bradford audiences
  • Walthamstow Art Trail to return in June for 20th anniversary
  • Finance minister highlights AI capacity building for developing nations at G7
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
Finance ProFinance Pro
  • Home
  • Art Gallery
  • Art Investment
  • Art Stocks
  • Cryptocurrency
  • Finance
  • Investing in Art
  • Investments
Finance Pro
Home»Cryptocurrency»Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data
Cryptocurrency

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data

December 16, 20253 Mins Read

[ad_1]

Dec 16, 2025Ravie LakshmananCybersecurity / Cryptocurrency

Cybersecurity researchers have discovered a new malicious NuGet package that typosquats and impersonates the popular .NET tracing library and its author to sneak in a cryptocurrency wallet stealer.

The malicious package, named “Tracer.Fody.NLog,” remained on the repository for nearly six years. It was published by a user named “csnemess” on February 26, 2020. It masquerades as “Tracer.Fody,” which is maintained by “csnemes.” The package continues to remain available as of writing, and has been downloaded at least 2,000 times, out of which 19 took place over the last six weeks for version 3.2.4.

Cybersecurity

“It presents itself as a standard .NET tracing integration but in reality functions as a cryptocurrency wallet stealer,” Socket security researcher Kirill Boychenko said. “Inside the malicious package, the embedded Tracer.Fody.dll scans the default Stratis wallet directory, reads *.wallet.json files, extracts wallet data, and exfiltrates it together with the wallet password to threat actor-controlled infrastructure in Russia at 176.113.82[.]163.”

The software supply chain security company said the threat leveraged a number of tactics that allowed it to elude casual review, including mimicking the legitimate maintainer by using a name that differs by a single letter (“csnemes” vs. “csnemess”), using Cyrillic lookalike characters in the source code, and hiding the malicious routine within a generic helper function (“Guard.NotNull”) that’s used during regular program execution.

Once a project references the malicious package, it activates its behavior by scanning the default Stratis wallet directory on Windows (“%APPDATA%\\StratisNode\\stratis\\StratisMain”), reads *.wallet.json files and in-memory passwords, and exfiltrates them to the Russian-hosted IP address.

“All exceptions are silently caught, so even if the exfiltration fails, the host application continues to run without any visible error while successful calls quietly leak wallet data to the threat actor’s infrastructure,” Boychenko said.

Cybersecurity

Socket said the same IP address was previously put to use in December 2023 in connection with another NuGet impersonation attack in which the threat actor published a package named “Cleary.AsyncExtensions” under the alias “stevencleary” and incorporated functionality to siphon wallet seed phrases. The package was so-called to disguise itself as the AsyncEx NuGet library.

The findings once illustrate how malicious typosquats mirroring legitimate tools can stealthily operate without attracting any attention across the open-source repository ecosystems.

“Defenders should expect to see similar activity and follow-on implants that extend this pattern,” Socket said. “Likely targets include other logging and tracing integrations, argument validation libraries, and utility packages that are common in .NET projects.”

[ad_2]

Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026 Cryptocurrency

Bitcoin slumps to a two-week low as Iran war builds pressure on cryptocurrency

May 17, 2026 Cryptocurrency

Investors Flocking to Super-Anonymous Cryptocurrency Used for the Sketchiest Stuff Imaginable

May 17, 2026 Cryptocurrency

#CryptoCornerSeason2 | Crypto Corner powered by Binance Kea Credit's Jo DSilva To @CNBCTV18News – Real World Asset Tokenisation has hit $370 bn as of April 2026 – BCG is estimating assets worth $60-64 tn to come on chain by end of 2030 Manisha – LinkedIn

May 15, 2026 Cryptocurrency

Australia’s Capital Gains Tax Overhaul Set to Impact Cryptocurrency Investors

May 14, 2026 Cryptocurrency

T3 Financial Crime Unit Seizes Over $450M in Criminal Cryptocurrency Operations

May 14, 2026 Cryptocurrency
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026 Investments 1 Min Read

[ad_1] During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting…

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026

What actually is ‘reasonable financial provision’ for the purposes of the Inheritance (Provision for Family and Dependants) Act 1975? McDaniel v Talbot & Anor [2026] EWHC 928 (Ch) – Today's Wills and Probate

May 20, 2026
Our Picks

UK finance ministry presses supermarkets to cap food prices, sources say

May 19, 2026

Welsh painter and art teacher has enjoyed a successful 14 months in Shetland, before recently receiving the dream offer of opening her own gallery in Fife

May 19, 2026

ChatGPT Can Now Access Your Bank Account — As OpenAI Expands Into Personal Finance

May 19, 2026
Latest updates

During Infrastructure Week, Governor Newsom announces $540 million investment to improve infrastructure statewide, connecting Californians to reliable and safe transportation – California State Portal | CA.gov

May 20, 2026

Mexico Data Center Market Investment & Growth Report 2026-2031 Featuring Key DC Investors – AWS, Ascenty, Equinix, Google, HostDime, KIO, Mexico Telecom Partners, Microsoft, ODATA, Scala – Yahoo Finance UK

May 20, 2026

EU Opens Public Consultation to Review MiCA Cryptocurrency Regulations

May 20, 2026
Weekly Updates

Americana and Farm Frites to expand MENA footprint with $100 million investment (SAR 375 million) in a state-of-the-art Greenfield Frozen French Fries factory in the Kingdom of Saudi Arabia – The Malaysian Reserve

November 27, 2024

Galaxy Digital Recruiting Investors for $100 Million Crypto Fund

April 3, 2024

RMC MINING (teaches you how to use XRP) – The fastest way to mine cryptocurrency

September 14, 2025
  • Privacy Policy
  • Terms and Conditions
  • Get In Touch
© 2026 Finance Pro

Type above and press Enter to search. Press Esc to cancel.