A malicious NuGet package named Tracer.Fody.NLog was discovered impersonating the legitimate .NET tracing library Tracer.Fody, using typosquatting and homoglyph techniques to deceive developers. Published in 2020 under the alias csnemess—a near match to the real maintainer's handle—the package successfully evaded detection for over five years, accumulating approximately 2,000 downloads. The malware embedded within the package specifically targets Stratis cryptocurrency wallets, lying dormant until triggered by certain conditions, and then silently exfiltrating wallet data and passwords to attacker-controlled infrastructure in Russia.
The attack leverages a common coding pattern by hooking into the Guard.NotNull<T> helper method, activating when an object with a WalletPassword property is processed. The malicious code scans the default Stratis wallet directory, reads *.wallet.json files, and transmits sensitive information without alerting the user or generating logs. The sophisticated use of lookalike package names, maintainer aliases, and Unicode homoglyphs in code identifiers made the threat difficult to detect during manual reviews, highlighting the persistent risks of supply chain attacks in open-source ecosystems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
At the time of public reporting, the rogue Tracer.Fody.NLog package remained accessible on the NuGet repository. Researchers warned that similar typosquatting supply-chain attacks could target other widely used .NET libraries.
By mid-December 2025, security researchers identified that Tracer.Fody.NLog was not a legitimate tracing component but a cryptocurrency wallet stealer targeting Stratis wallets on Windows. Analysis showed it exfiltrated wallet files and passwords to infrastructure in Russia while using silent exception handling and hidden helper methods to evade detection.
In December 2023, another malicious NuGet package, Cleary.AsyncExtensions, was linked to the same Russian IP address and threat infrastructure. That package also exfiltrated sensitive cryptocurrency wallet information, indicating a broader campaign by the same actor.
Over the following years, the malicious package stayed available on the NuGet repository and was downloaded roughly 2,000 times. Its long dwell time increased the likelihood of developer adoption and downstream exposure in .NET projects.
A threat actor published the rogue NuGet package Tracer.Fody.NLog in February 2020, typosquatting the legitimate Tracer.Fody library and impersonating its maintainer. The package used homoglyphs and disguised itself as a benign .NET tracing integration while embedding wallet-stealing functionality.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.