logo

Malicious Braintree.Net Typosquat Steals PAN, CVV, and Payment Gateway Credentials

ID: 9b846ccc-0949-5f5c-9572-5c1a1ef8f588

STIX ID: report--9b846ccc-0949-5f5c-9572-5c1a1ef8f588

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-10

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

A malicious NuGet typosquat, published as "Braintree.Net", impersonates the official PayPal Braintree SDK and contains a multi-stage .NET implant that silently harvests environment metadata, merchant API keys, and full payment card data, exfiltrating to attacker-controlled infrastructure (api.348672-shakepay.com). The package uses module initializers and instrumented gateway methods to activate on assembly load or during production payment operations, is paired with a DependencyInjector.Core token harvester, and was reported to NuGet by Socket with recommended mitigations including dependency auditing, key rotation, and scanning for unexpected module initializers and telemetry endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.