Malicious Package Affecting stripeapi.net package, versions [50.4.1][0.0.534][0.0.518][0.0.510][0.0.504][0.0.501][0.0.500][0.0.499][0.0.498][0.0.497][0.0.496][0.0.495][0.0.494][0.0.493][0.0.492][0.0.491][0.0.490][0.0.489][0.0.488][0.0.487][0.0.486][0.0.485][0.0.484][0.0.483][0.0.482][0.0.481][0.0.480][0.0.479][0.0.478][0.0.477][0.0.476][0.0.475][0.0.474][0.0.473][0.0.472][0.0.471][0.0.470][0.0.469][0.0.468][0.0.467][0.0.466][0.0.465][0.0.464][0.0.463][0.0.462][0.0.461][0.0.460][0.0.459][0.0.458][0.0.457][0.0.456][0.0.455][0.0.454][0.0.453][0.0.452][0.0.451][0.0.450][0.0.449][0.0.448][0.0.447][0.0.446][0.0.445][0.0.444][0.0.443][0.0.442][0.0.441][0.0.440][0.0.439][0.0.438][0.0.437][0.0.436][0.0.435][0.0.434][0.0.433][0.0.432][0.0.431][0.0.430][0.0.429][0.0.428][0.0.427][0.0.426][0.0.425][0.0.424][0.0.423][0.0.422][0.0.421][0.0.420][0.0.419][0.0.418][0.0.417][0.0.416][0.0.415][0.0.414][0.0.413][0.0.412][0.0.411][0.0.410][0.0.409][0.0.408][0.0.407]


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-STRIPEAPINET-18138141
  • published22 Jul 2026
  • disclosed20 Jul 2026
  • creditUnknown

Introduced: 20 Jul 2026

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the stripeapi.net package.

Overview

stripeapi.net is a malicious package. This package contains malicious code, and its content was removed from the official package manager. While this package might be attempting to impersonate a valid organization, there is no connection between that organization and this package authorship.

CVSS Base Scores

version 4.0
version 3.1