Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

2026-07-22T07:24:17Zb7aac276fb4dbd6bd773d8be4ff86373fcba33ac665009664a2cb0fcb77bad68
7-zipactive-exploitationai-agent-abusecalendar-c2github-malwarehoneypot/telemetry-evasionmodel-theftnugetpalo-alto-pan-osphishing-toolkitprompt-injectionransomwareremote-code-executionrubygemssandbox-escapeservicenowsharepointsnmp-command-injectionsupply-chainwordPress

What happened

This feed highlights a spike in high-impact supply-chain and AI-related attacks alongside multiple critical RCEs now being actively exploited. Notable items: a trojanized NuGet package (Newtonsoftt.Json.Net) and malicious RubyGems/GitHub repos (SleeperGem, FakeGit) delivering loaders; WordPress wp2shell (CVE-2026-63030, CVE-2026-60137) and SharePoint deserialization RCE (CVE-2026-50522) under active exploitation; ServiceNow sandbox escape (CVE-2026-6875) in the wild; a 7-Zip XZ extraction RCE (CVE-2026-14266); and a PAN-OS authentication bypass (CVE-2026-0257) used to plant Qilin ransomware. A

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b7aac276fb4dbd6bd773d8be4ff86373fcba33ac665009664a2cb0fcb77bad68
Enrichment time
2026-07-22T07:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library · Baitaphish