Malicious Braintree.Net Typosquat Steals PAN, CVV, and Payment Gateway Credentials
ID: 9b846ccc-0949-5f5c-9572-5c1a1ef8f588
STIX ID: report--9b846ccc-0949-5f5c-9572-5c1a1ef8f588
Feed Name: GBHackers
A malicious NuGet typosquat, published as "Braintree.Net", impersonates the official PayPal Braintree SDK and contains a multi-stage .NET implant that silently harvests environment metadata, merchant API keys, and full payment card data, exfiltrating to attacker-controlled infrastructure (api.348672-shakepay.com). The package uses module initializers and instrumented gateway methods to activate on assembly load or during production payment operations, is paired with a DependencyInjector.Core token harvester, and was reported to NuGet by Socket with recommended mitigations including dependency auditing, key rotation, and scanning for unexpected module initializers and telemetry endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
