Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Vadzo Imaging Validates Bolt-544CRS: 5MP Onsemi HyperLux LP AR0544 Color MIPI CSI-2 Camera with RK3588 Rockchip Processor

October 2, 2026

Bottomline Partners with Chainlink to Enhance

October 2, 2026

Can AAVE crypto reach $200? THIS overbought signal raises concerns

October 2, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Malicious NuGet Package Targets Stripe Developers
Malicious NuGet Package Targets Stripe Developers
Security and Privacy

Malicious NuGet Package Targets Stripe Developers

February 25, 2026No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A malicious NuGet package designed to mimic Stripe’s official .NET library has been uncovered by cybersecurity researchers, marking a shift in tactics from earlier cryptocurrency-focused campaigns to the broader financial sector.

The package, named StripeApi.Net, impersonated Stripe.net, the legitimate helper library used to integrate Stripe payments into Microsoft .NET applications.

With more than 74 million downloads, Stripe.net is widely adopted by developers building payment, billing and subscription systems. This made the malicious package particularly dangerous.

Typosquatting Campaign Targets Developers

According to a new advisory by ReversingLabs, rather than attempting to breach Stripe’s official package, the threat actors used typosquatting and published a similarly named package to trick developers into installing it.

The fake listing closely resembled the genuine NuGet page. It used the same icon, near-identical documentation and matching tags.

The publisher name, “StripePayments,” was chosen to appear credible, though the account retained the default NuGet profile image instead of Stripe’s logo.

Researchers said that the malicious package showed more than 180,000 downloads. However, they also noted that figures appear to have been artificially inflated.

Instead of accumulating large download counts across a small number of versions, the threat actors spread roughly 300 downloads each across 506 versions to create the impression of steady use.

Hidden Code Exfiltrated API Keys

A deeper inspection revealed that the package contained largely legitimate Stripe code, but with subtle modifications. Critical methods were altered to capture API tokens when the StripeClient class was initialized.

Read more on attacks targeting Stripe customers: Stripe API Skimming Campaign Unveils New Techniques for Theft 

Once obtained, the stolen API keys and a machine identifier were transmitted to a Supabase database controlled by the attackers. Supabase provides managed PostgreSQL services, making it convenient as data collection infrastructure.

See also  Millions of Email Servers at Risk from Cryptomining Worm

Despite the inflated download count, ReversingLabs said it is unlikely any developers were compromised. The company reported the package shortly after its publication on February 16, and NuGet administrators removed it shortly after receiving the notification. An examination of the associated Supabase database found no stolen tokens, only a test entry.

ReversingLabs warned that the incident highlights persistent third-party risk in modern software development. 

“The increasing frequency of such campaigns requires a shift in thinking by developers,” the team warned. “Legitimate packages may… be compromised and traffic malicious code into legitimate development pipelines, as the recent Shai- hulud npm malware outbreak showed.”

Image credit: Mamun_Sheikh / Shutterstock.com

Source link

Developers Malicious NuGet Package Stripe Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

The $459,000 Bot Hacker Was a Customer First, Researchers Say

October 2, 2026

Metamask Pulls Validators as Meager ETH Theft Sounds Big Alarm

October 1, 2026

NEAR Intents Bug Sends $3.8M Racing Across Crypto Networks

October 1, 2026

New stablecoin Open USD goes live as Coinbase, Mastercard, Stripe and Visa commit $1 billion to liquidity

October 1, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Bit Digital Expands AI and HPC Footprint, Signs $700 Million Agreement With Boosteroid

August 21, 2024

Bitcoin options surge to all-time high as price briefly tops $44,000

December 7, 2023

eToro ending US customers’ access to four cryptocurrencies

June 13, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Vadzo Imaging Validates Bolt-544CRS: 5MP Onsemi HyperLux LP AR0544 Color MIPI CSI-2 Camera with RK3588 Rockchip Processor

October 2, 2026

Bottomline Partners with Chainlink to Enhance

October 2, 2026

Can AAVE crypto reach $200? THIS overbought signal raises concerns

October 2, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$86,291.002.80%
  • ethereumEthereum(ETH)$2,743.061.58%
  • tetherTether(USDT)$1.000.01%
  • binancecoinBNB(BNB)$775.900.76%
  • rippleXRP(XRP)$1.543.13%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$121.923.33%
  • tronTRON(TRX)$0.3349650.63%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.020.00%
  • zcashZcash(ZEC)$1,381.86-0.88%