A typosquatted NuGet package named Braintree.Net was identified as a malicious counterfeit of the legitimate Braintree .NET SDK, targeting payment-processing applications and silently stealing sensitive data while preserving normal transaction flows. Reported malicious versions include 3.35.8, 3.35.9, 3.36.0, and 3.36.1, with related exposure through malicious DependencyInjector.Core releases and transitive dependencies including sipnet and sipnet.openai.realtime. The package reportedly harvested payment-card numbers, CVVs, expiration dates, customer and transaction details, Braintree merchant API keys, environment variables, and cloud or container secrets, while package metadata referenced the real Braintree GitHub repository to appear legitimate.
The malware reportedly used XOR obfuscation to conceal its command-and-control infrastructure and checked whether it was running in a production environment before activating key collection behavior. Reported exfiltration infrastructure included api.348672-shakepay[.]com and the paths /api/card, /api/account, and /api/analytics/report. Organizations that installed the package were urged to remove the malicious dependencies, preserve forensic evidence, review outbound connections and payment activity, rotate exposed payment and infrastructure credentials, rebuild from clean dependencies, and scan affected developer and build systems for broader compromise.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A malicious NuGet package impersonating the legitimate Braintree .NET SDK was identified as stealing live payment-card data, merchant API keys, environment variables, and other host secrets while preserving normal payment functionality. Reporting also disclosed exfiltration infrastructure and noted XOR-obfuscated command-and-control behavior and production-environment checks.
The first malicious version of the typosquatted NuGet package Braintree.Net was reportedly published, beginning a supply-chain campaign against .NET payment-processing applications. Reported malicious versions included 3.35.8, 3.35.9, 3.36.0, and 3.36.1.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcetrojan-killer.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.