Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
ID: 59cca473-da6b-543e-8b73-d54b93cd7568
STIX ID: report--59cca473-da6b-543e-8b73-d54b93cd7568
Feed Name: The Hacker News
Cybersecurity researchers discovered a malicious typosquatted NuGet package, StripeApi.Net, impersonating the legitimate Stripe.net library to target the financial sector. The package replicated normal functionality while modifying critical methods to collect and exfiltrate users' Stripe API tokens; the actor also inflated download counts (~180,000 split across 506 versions). ReversingLabs reported and prompted removal of the package shortly after discovery, preventing wider impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
