logo

Malicious NuGet package targets Stripe

ID: 1cae0eee-b816-5686-8edd-41cf2b5e046a

STIX ID: report--1cae0eee-b816-5686-8edd-41cf2b5e046a

Feed Name: ReversingLabs Blog

Threat Score
55/100

Date Published: 2026-02-25

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs discovered a typosquatting NuGet package, StripeAPI.net, that closely mimics the popular Stripe.net library and contains injected code to capture Stripe API tokens and exfiltrate them to a Supabase-hosted database; the package used visual spoofing and inflated version/download counts to appear legitimate, but investigators found no evidence of real exfiltrated tokens and NuGet removed the package after notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.