logo

Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens

ID: 59cca473-da6b-543e-8b73-d54b93cd7568

STIX ID: report--59cca473-da6b-543e-8b73-d54b93cd7568

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers discovered a malicious typosquatted NuGet package, StripeApi.Net, impersonating the legitimate Stripe.net library to target the financial sector. The package replicated normal functionality while modifying critical methods to collect and exfiltrate users' Stripe API tokens; the actor also inflated download counts (~180,000 split across 506 versions). ReversingLabs reported and prompted removal of the package shortly after discovery, preventing wider impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.