B
今週中
NuGetリポジトリにおいて、人気のライブラリ「Newtonsoft.Json」を装ったタイポスクワッティングパッケージ「Newtonsoftt.Json.Ne…
📌 一言でいうと
NuGetリポジトリにおいて、人気のライブラリ「Newtonsoft.Json」を装ったタイポスクワッティングパッケージ「Newtonsoftt.Json.Net」が発見されました。このパッケージは、オンラインベッティングプラットフォーム「Digitain」のゲーム結果を操作し、結果を攻撃者のサーバーへ送信するトロイの木馬が含まれています。約1,200回ダウンロードされており、現在は所有者によって非公開化されていますが、アーティファクトは依然として利用可能です。
🔍該当判定
- 開発プロジェクトで、NuGetから 'Newtonsoftt.Json.Net' (tが2つの綴り) というパッケージをインストールしている
- 開発プロジェクトで、Newtonsoft.Json のフォーク版(派生版)を意図的に導入して利用している
- 社内で 'Digitain' というオンラインベッティング(賭け)プラットフォームを利用している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. 依存関係に 'Newtonsoftt.Json.Net' (tが2つの綴り) が含まれていないか確認し、含まれている場合は直ちに削除すること。2. パッケージ導入時のタイポ(綴り間違い)に注意し、公式の信頼できるソースからのみライブラリをインストールすること。3. 開発環境におけるパッケージ管理ツールの監査を強化すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】NuGet タイポスクワッティングパッケージ(Newtonsoftt.Json.Net)への対応について
お疲れさまです。NuGetリポジトリにおけるサプライチェーン攻撃に関する情報共有です。
■ 概要
人気のライブラリ「Newtonsoft.Json」に酷似した名称の悪意あるパッケージ「Newtonsoftt.Json.Net」が配布されていました。このパッケージは、特定のベッティングプラットフォーム(Digitain)の操作およびデータの外部送信を行うトロイの木馬として機能します。
■ 影響範囲
- 対象パッケージ: Newtonsoftt.Json.Net
- 対象バージョン: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, 11.0.11
■ 対応手順
1. プロジェクトの依存関係ファイル(csproj, packages.config等)を確認し、誤って「Newtonsoftt.Json.Net」を導入していないか点検してください。
2. 該当パッケージが検出された場合は、直ちに削除し、正規の「Newtonsoft.Json」へ差し替えてください。
3. 開発チームに対し、パッケージ導入時の名称確認を徹底するよう周知してください。
■ 参考情報
- JFrog Security Research
対応優先度: 中
対応期限: 速やかに
お疲れさまです。NuGetリポジトリにおけるサプライチェーン攻撃に関する情報共有です。
■ 概要
人気のライブラリ「Newtonsoft.Json」に酷似した名称の悪意あるパッケージ「Newtonsoftt.Json.Net」が配布されていました。このパッケージは、特定のベッティングプラットフォーム(Digitain)の操作およびデータの外部送信を行うトロイの木馬として機能します。
■ 影響範囲
- 対象パッケージ: Newtonsoftt.Json.Net
- 対象バージョン: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, 11.0.11
■ 対応手順
1. プロジェクトの依存関係ファイル(csproj, packages.config等)を確認し、誤って「Newtonsoftt.Json.Net」を導入していないか点検してください。
2. 該当パッケージが検出された場合は、直ちに削除し、正規の「Newtonsoft.Json」へ差し替えてください。
3. 開発チームに対し、パッケージ導入時の名称確認を徹底するよう周知してください。
■ 参考情報
- JFrog Security Research
対応優先度: 中
対応期限: 速やかに
Subject: [Security Alert] Typosquatting Package 'Newtonsoftt.Json.Net' on NuGet
Dear IT/Security Team,
We are sharing information regarding a supply chain attack targeting the NuGet ecosystem.
■ Overview
A malicious package named 'Newtonsoftt.Json.Net' has been identified as a typosquatting attempt against the widely used 'Newtonsoft.Json' library. This trojanized fork is designed to rig results on the Digitain betting platform and exfiltrate data to an attacker-controlled server.
■ Scope
- Affected Package: Newtonsoftt.Json.Net
- Affected Versions: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, 11.0.11
■ Action Items
1. Audit project dependency files (e.g., .csproj, packages.config) to ensure 'Newtonsoftt.Json.Net' is not being used.
2. If detected, immediately remove the malicious package and replace it with the official 'Newtonsoft.Json' library.
3. Remind development teams to verify package names carefully before installation.
■ Reference
- JFrog Security Research
Priority: Medium
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a supply chain attack targeting the NuGet ecosystem.
■ Overview
A malicious package named 'Newtonsoftt.Json.Net' has been identified as a typosquatting attempt against the widely used 'Newtonsoft.Json' library. This trojanized fork is designed to rig results on the Digitain betting platform and exfiltrate data to an attacker-controlled server.
■ Scope
- Affected Package: Newtonsoftt.Json.Net
- Affected Versions: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, 11.0.11
■ Action Items
1. Audit project dependency files (e.g., .csproj, packages.config) to ensure 'Newtonsoftt.Json.Net' is not being used.
2. If detected, immediately remove the malicious package and replace it with the official 'Newtonsoft.Json' library.
3. Remind development teams to verify package names carefully before installation.
■ Reference
- JFrog Security Research
Priority: Medium
Deadline: Immediate