• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
malicious stripeapi nuget package mimicked official library and stole api

Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens

You are here: Home / General Cyber Security News / Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
February 26, 2026

Cybersecurity researchers have disclosed details of a new malicious package discovered on the NuGet Gallery, impersonating a library from financial services firm Stripe in an attempt to target the financial sector.

The package, codenamed StripeApi.Net, attempts to masquerade as Stripe.net, a legitimate library from Stripe that has over 75 million downloads. It was uploaded by a user named StripePayments on February 16, 2026. The package is no longer available.

“The NuGet page for the malicious package is set up to resemble the official Stripe.net package as closely as possible,” ReversingLabs Petar Kirhmajer said. “It uses the same icon as the legitimate package and contains a nearly identical readme, only swapping the ‘Stripe.net’ references to read ‘Stripe-net.'”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


In a further effort to lend credibility to the typosquatted package, the threat actor behind the campaign is said to have artificially inflated the download count to more than 180,000. But in an interesting twist, the downloads were split across 506 versions, with each version recording about 300 downloads on average.

Cybersecurity

The package replicates some of the legitimate Stripe package’s functionality, but also modifies certain critical methods to collect and transfer sensitive data, including the user’s Stripe API token, back to the threat actor. With the rest of the codebases remaining fully functional, it’s unlikely to attract any suspicion from unsuspecting developers who may have inadvertently downloaded it.

ReversingLabs said it discovered and reported the package “relatively soon” after it was initially released, causing it to be taken before it could inflict any serious damage.

The software supply chain security company also noted that the activity marks a shift from prior campaigns that have leveraged bogus NuGet packages to target the cryptocurrency ecosystem and facilitate wallet key theft.

“Developers who mistakenly download and integrate a typosquatted library like StripeAPI.net will still have their applications compile successfully and function as intended,” Kirhmajer said. “Payments would process normally and, from the developer’s perspective, nothing would appear broken. In the background, however, sensitive data is being secretly copied and exfiltrated by malicious actors.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cisco sd wan zero day cve 2026 20127 exploited since 2023 for admin access Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
  • Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited Since 2023 for Admin Access
  • Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries
  • Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
  • SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
  • Top 5 Ways Broken Triage Increases Business Risk Instead of Reducing It
  • Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
  • Manual Processes Are Putting National Security at Risk
  • Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker
  • SolarWinds Patches 4 Critical Serv-U 15.5 Flaws Allowing Root Code Execution

Copyright © TheCyberSecurity.News, All Rights Reserved.