Malicious NuGet Package Targets Stripe Developers
ID: cbc356ed-2cbf-5cb8-9d4d-08636b4b21a1
STIX ID: report--cbc356ed-2cbf-5cb8-9d4d-08636b4b21a1
Feed Name: Infosecurity Magazine (News)
Threat Score
A malicious typosquatting NuGet package, StripeApi.Net, impersonated the widely used Stripe.net library and included subtle modifications that captured API keys at StripeClient initialization and transmitted them to an attacker-controlled Supabase database; ReversingLabs reported and NuGet removed the package shortly after publication, and investigators found no confirmed stolen tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
