By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
Computing

Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens

News Room
Last updated: 2026/02/26 at 6:14 AM
News Room Published 26 February 2026
Share
Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens
SHARE

Ravie LakshmananFeb 26, 2026Malware / Software Security

Cybersecurity researchers have disclosed details of a new malicious package discovered on the NuGet Gallery, impersonating a library from financial services firm Stripe in an attempt to target the financial sector.

The package, codenamed StripeApi.Net, attempts to masquerade as Stripe.net, a legitimate library from Stripe that has over 75 million downloads. It was uploaded by a user named StripePayments on February 16, 2026. The package is no longer available.

“The NuGet page for the malicious package is set up to resemble the official Stripe.net package as closely as possible,” ReversingLabs Petar Kirhmajer said. “It uses the same icon as the legitimate package and contains a nearly identical readme, only swapping the ‘Stripe.net’ references to read ‘Stripe-net.'”

In a further effort to lend credibility to the typosquatted package, the threat actor behind the campaign is said to have artificially inflated the download count to more than 180,000. But in an interesting twist, the downloads were split across 506 versions, with each version recording about 300 downloads on average.

The package replicates some of the legitimate Stripe package’s functionality, but also modifies certain critical methods to collect and transfer sensitive data, including the user’s Stripe API token, back to the threat actor. With the rest of the codebases remaining fully functional, it’s unlikely to attract any suspicion from unsuspecting developers who may have inadvertently downloaded it.

ReversingLabs said it discovered and reported the package “relatively soon” after it was initially released, causing it to be taken before it could inflict any serious damage.

The software supply chain security company also noted that the activity marks a shift from prior campaigns that have leveraged bogus NuGet packages to target the cryptocurrency ecosystem and facilitate wallet key theft.

“Developers who mistakenly download and integrate a typosquatted library like StripeAPI.net will still have their applications compile successfully and function as intended,” Kirhmajer said. “Payments would process normally and, from the developer’s perspective, nothing would appear broken. In the background, however, sensitive data is being secretly copied and exfiltrated by malicious actors.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Samsung Galaxy S26 pre-orders: Get double storage across the range Samsung Galaxy S26 pre-orders: Get double storage across the range
Next Article Anthropic acquires computer-use AI startup Vercept after Meta poached one of its founders |  News Anthropic acquires computer-use AI startup Vercept after Meta poached one of its founders | News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

SEO A/B Testing: 5 Easy Experiments to Drive Traffic | WordStream
SEO A/B Testing: 5 Easy Experiments to Drive Traffic | WordStream
Computing
Pixel’s March update is causing some phones to boot loop endlessly, and no one knows why
Pixel’s March update is causing some phones to boot loop endlessly, and no one knows why
News
OpenClaw Changed How We Use AI. KiloClaw Made It Effortless to Get Started | HackerNoon
OpenClaw Changed How We Use AI. KiloClaw Made It Effortless to Get Started | HackerNoon
Computing
iPhone Fold enters manufacturing test phase right on schedule
iPhone Fold enters manufacturing test phase right on schedule
News

You Might also Like

SEO A/B Testing: 5 Easy Experiments to Drive Traffic | WordStream
Computing

SEO A/B Testing: 5 Easy Experiments to Drive Traffic | WordStream

15 Min Read
OpenClaw Changed How We Use AI. KiloClaw Made It Effortless to Get Started | HackerNoon
Computing

OpenClaw Changed How We Use AI. KiloClaw Made It Effortless to Get Started | HackerNoon

12 Min Read
Tiny Corp Begins Accepting Pre-Orders For Their M Exabox
Computing

Tiny Corp Begins Accepting Pre-Orders For Their $10M Exabox

2 Min Read
Huawei Enjoy 70X smartphone to launch on January 3 with Kirin 8000A processor · TechNode
Computing

Huawei Enjoy 70X smartphone to launch on January 3 with Kirin 8000A processor · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?