Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

Inside Bhadohi’s Carpet Economic system | YourStory

February 26, 2026

The CBN Has a Plan to Make Regulation Work for Fintechs. Right here Is What It Seems Like.

February 26, 2026

Enhancing passenger motion throughout transport networks

February 26, 2026
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • Inside Bhadohi’s Carpet Economic system | YourStory
  • The CBN Has a Plan to Make Regulation Work for Fintechs. Right here Is What It Seems Like.
  • Enhancing passenger motion throughout transport networks
  • Meta and AMD Companion for Longterm AI Infrastructure Settlement – MassRobotics
  • How big galaxies might kind simply 1.4 billion years after the Large Bang
  • Last DX4000CL Headphones Characteristic New Dynamic Drivers
  • Kenya’s Pesalink plugs into Africa’s cross-border funds community
  • Steve Clean Time to Transfer On – The Cause Relationships Finish
Thursday, February 26
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Malicious StripeApi NuGet Package deal Mimicked Official Library and Stole API Tokens
Cybersecurity & Digital Rights

Malicious StripeApi NuGet Package deal Mimicked Official Library and Stole API Tokens

NextTechBy NextTechFebruary 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Malicious StripeApi NuGet Package deal Mimicked Official Library and Stole API Tokens
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananFeb 26, 2026Malware / Software program Safety

Cybersecurity researchers have disclosed particulars of a brand new malicious bundle found on the NuGet Gallery, impersonating a library from monetary providers agency Stripe in an try to focus on the monetary sector.

The bundle, codenamed StripeApi.Internet, makes an attempt to masquerade as Stripe.internet, a respectable library from Stripe that has over 75 million downloads. It was uploaded by a consumer named StripePayments on February 16, 2026. The bundle is not accessible.

“The NuGet web page for the malicious bundle is ready as much as resemble the official Stripe.internet bundle as carefully as potential,” ReversingLabs Petar Kirhmajer stated. “It makes use of the identical icon because the respectable bundle and accommodates a virtually an identical readme, solely swapping the ‘Stripe.internet’ references to learn ‘Stripe-net.'”

In an extra effort to lend credibility to the typosquatted bundle, the menace actor behind the marketing campaign is alleged to have artificially inflated the obtain rely to greater than 180,000. However in an attention-grabbing twist, the downloads have been cut up throughout 506 variations, with every model recording about 300 downloads on common.

The bundle replicates a few of the respectable Stripe bundle’s performance, but in addition modifies sure crucial strategies to gather and switch delicate knowledge, together with the consumer’s Stripe API token, again to the menace actor. With the remainder of the codebases remaining absolutely practical, it is unlikely to draw any suspicion from unsuspecting builders who could have inadvertently downloaded it.

Stripe

ReversingLabs stated it found and reported the bundle “comparatively quickly” after it was initially launched, inflicting it to be taken earlier than it may inflict any critical injury.

The software program provide chain safety firm additionally famous that the exercise marks a shift from prior campaigns which have leveraged bogus NuGet packages to focus on the cryptocurrency ecosystem and facilitate pockets key theft.

“Builders who mistakenly obtain and combine a typosquatted library like StripeAPI.internet will nonetheless have their purposes compile efficiently and performance as meant,” Kirhmajer stated. “Funds would course of usually and, from the developer’s perspective, nothing would seem damaged. Within the background, nevertheless, delicate knowledge is being secretly copied and exfiltrated by malicious actors.”

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the newest breakthroughs, get unique updates, and join with a world community of future-focused thinkers.
Unlock tomorrow’s developments in the present day: learn extra, subscribe to our publication, and change into a part of the NextTech group at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

RAMP Discussion board Seizure Fractures Ransomware Ecosystem

February 26, 2026

Handbook Processes Are Placing Nationwide Safety at Danger

February 25, 2026

AI Selections Should Be Provable

February 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Economy News

Inside Bhadohi’s Carpet Economic system | YourStory

By NextTechFebruary 26, 2026

Sant Ravidas Nagar, broadly often known as Bhadohi, Uttar Pradesh — carpets are usually not…

The CBN Has a Plan to Make Regulation Work for Fintechs. Right here Is What It Seems Like.

February 26, 2026

Enhancing passenger motion throughout transport networks

February 26, 2026
Top Trending

Inside Bhadohi’s Carpet Economic system | YourStory

By NextTechFebruary 26, 2026

Sant Ravidas Nagar, broadly often known as Bhadohi, Uttar Pradesh — carpets…

The CBN Has a Plan to Make Regulation Work for Fintechs. Right here Is What It Seems Like.

By NextTechFebruary 26, 2026

On February 2, 2026, the Central Financial institution of Nigeria (CBN) launched…

Enhancing passenger motion throughout transport networks

By NextTechFebruary 26, 2026

Switch Show within the Timetable visualises connectivity immediately within the timetable so…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!