Malicious StripeApi NuGet Package Mimicked Official Library and Stole API Tokens

The Hacker NewsThe Hacker News
February 26, 2026 at 10:09 AM

Cybersecurity researchers have disclosed details of a new malicious package discovered on the NuGet Gallery, impersonating a library from financial services firm Stripe in an attempt to target the financial sector. The package, codenamed StripeApi.Net, attempts to masquerade as Stripe.net, a legitimate library from Stripe that has over 75 million downloads. It was uploaded by a user named