Fake Braintree NuGet Packages Steal Payment Card Data and Merchant Credentials

Summary
Socket researchers found malicious NuGet packages impersonating Braintree that steal payment card data, merchant credentials, and host secrets. The packages send data to attacker-controlled infrastructure; Socket reported them to NuGet and recommends removal and key and
Key points
- The Braintree.Net typosquat mimics PayPal Braintree’s official SDK. Malicious versions 3.35.8–3.36.1 were identified; Socket says the first appeared on July 3, 2026.
- Payment hooks send card numbers, CVVs, expiration dates, and related transaction data to attacker-controlled infrastructure when configured for production.
- The package also exfiltrates merchant IDs and API keys; its DependencyInjector.Core companion harvests environment variables, application configuration, cloud metadata, and other secrets on assembly load.
- The malicious endpoint is api.348672-shakepay[.]com. Related packages, including SipNet versions 12.8.4–12.8.7, can introduce the companion harvester.
- Socket reported the packages to NuGet and requested removal. It recommends removing affected packages, rotating credentials, assessing possible card-data exposure, auditing dependencies, and blocking the domain.
Article Details
- Attack Vectors
- NuGet package typosquatting and metadata impersonation lure developers into installing Braintree.Net instead of the official package. Copied documentation, matching APIs, and inflated download counts reinforce the deception.
- Confirmed malicious versions are Braintree.Net 3.35.8–3.36.1 and DependencyInjector.Core 1.0.0, 1.3.0, 1.4.0, and 1.4.1.
- Payment gateway hooks intercept full card numbers, CVVs, expiry dates, and transaction details before allowing legitimate payment requests to proceed. These hooks activate only for production configurations.
- A modified private-key property setter sends merchant identifiers, public keys, and private keys to the attacker when a production gateway is configured.
- Assembly module initializers launch an environment and configuration harvester without requiring explicit application calls. Unlike the payment hooks, this harvesting is not restricted to production configurations.
- SipNet 12.8.4–12.8.7 introduce the malicious dependency for .NET 8/9/10 targets despite their own assembly being a clean recompile.
- SipNet.OpenAI.Realtime 12.8.3 is an indirect exposure route only when its resolved SipNet dependency reaches 12.8.4 or later; the reported default resolution to 12.8.3 does not load the harvester.
- Defensive Notes
- Remove the poisoned payment package from projects, central package management files, and CI restore caches, and replace it with the official package.
- Rotate merchant credentials and access tokens for environments that referenced the package; assume production keys were compromised if the gateway was configured for production.
- Treat payment card data as potentially disclosed when production requests passed card numbers or CVVs through the poisoned SDK. Engage applicable PCI incident response and notification processes.
- Audit lock files and dependency graphs for the companion harvester and the affected direct or transitive dependencies.
- Block the reported attacker domain and its subdomains, and inspect proxy and firewall logs for outbound POST requests and the reported X-Api-Key header.
- Hunt assemblies for the additional payment logger, module initializer, analytics reporter, and endpoint-obfuscation classes identified in the article.
- Do not interpret successful transactions or an absence of runtime errors as evidence of safety: exfiltration errors are silently suppressed.
- Sandbox-only applications using the affected .NET 8+ dependency can still expose host secrets even though production-only payment theft is inactive.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 348672-shakepay[.]com | Attacker-controlled domain impersonating the Shakepay brand; recommended for egress blocking. |
| HOSTNAME | api[.]348672-shakepay[.]com | Attacker-controlled endpoint receiving stolen payment data, merchant credentials, and environment secrets. |
| IPV4 | 104[.]21[.]89[.]51 | Cloudflare anycast address returned by passive DNS for the attacker-controlled domain; shared infrastructure, not an identified attacker origin. |
| IPV4 | 172[.]67[.]188[.]32 | Cloudflare anycast address returned by passive DNS for the attacker-controlled domain; shared infrastructure, not an identified attacker origin. |
| SHA256 | 064653872c1b4c3d5b5242627cda259056fed7159fcd2cc5a448981c9f81aeda | Listed hash of malicious Braintree.dll. |
| SHA256 | 220908e8c23c2332266ba1e984f839b9914c2e40a946b172f6d9b8b36728f98a | Listed hash of malicious Braintree.dll. |
| SHA256 | 2547382cd5151e2210c6349f17230ae3d1a59935e3b8d1757d72d9abd30ac858 | Listed hash of malicious Braintree.dll. |
| SHA256 | 5138ea25563be4ae8143b7a46c6bc42af00344678e6d4451ac596b5b5587c70e | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | 52aeb64f4199235704d0e4a6908c501c3b4bdd4a004a766a5ca55b9655b24775 | Listed hash of malicious Braintree.dll. |
| SHA256 | 531302fe3b8a8624aa468ee83707448fbd1db2eaa3f8d587331db2b17890f8ad | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | 5cae5ec54f450ef7483e265d289edc3877c17e3ae508c06e1679371aa1c1306f | Listed hash of malicious Braintree.dll. |
| SHA256 | 7a9f19ed663c1d4ee259ba0a10e93e1c9770812ce81f8c945140a452d17cb3c8 | Listed hash of malicious Braintree.dll. |
| SHA256 | 7c30f007af910886b46f6022dd724dd303ad2d5f983376d0547293f484d6ae71 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | 86d287eafecd542faec21a95522b3425000ae5d8650813a9987b7c10cf90fc7a | Listed hash of malicious Braintree.dll. |
| SHA256 | 9d8d79000f6413668429d851f7d8ce94cd1b61c3a421939cf34cec8d668f5388 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | 9dff477e6d30872669bb6186c67147a945d9de7e947eb7906afdb03c93901ead | Listed hash of malicious Braintree.dll. |
| SHA256 | b4a5bcf4ce8c9cc844c06f436d4c26b28cb408f7e4fd8990681336445493acc1 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | bfdaf869a3956b37bf416dcdafdad314e8de0215cfd8fd8b2bc7a4e5cd15a349 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | c3be125753aea85728a082823db77d833377d7e3eb199364aa49d1ff2535f53e | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | c9564621abec9bdb7ceb38bb1a2895a119772b7f830351272c13a3f4cd606b97 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | d6fbfada62639578b6a6e91786928705dd22bb14b0f030504ffbc974e23528bc | Listed hash of malicious Braintree.dll. |
| SHA256 | de6384e853dfc007205abb7b15b49eded2e3e977058600dece2c2e9190a5191a | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | e0c7797e7dba2056bc95bfddb96d9f07afb93988f108bc417c40cd05f7ae49a4 | Listed hash of malicious Braintree.dll. |
| SHA256 | eceab1132aacd803962fa173d1b2c43e225fcfa8b5d26d3efadad1b4de33d8ec | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | efec1e537445170a9aac11781c597cba5bd5d25b79ac3d65467d84f109d86fd4 | Listed hash of malicious DependencyInjector.Core.dll. |
| SHA256 | f181d57c29364aef01e3f72051ec2dc0da918d346e7e4d1377e13408afb8663a | Listed hash of malicious Braintree.dll. |
| SHA256 | f53359313ce9a9433651202a7ffbf155dc1379103796a45492a50edbf044d59d | Listed hash of malicious DependencyInjector.Core.dll. |
MITRE ATT&CK
T1005 · Data from Local SystemThe harvester collects raw configuration files, process environment values, and local application information for exfiltration.T1027 · Obfuscated Files or InformationThe companion harvester stores its analytics exfiltration URL as a ciphertext byte array protected with repeating-key XOR.T1036 · MasqueradingThe typosquat copies the legitimate SDK's public API, documentation, author identity, and repository metadata to appear authentic.T1041 · Exfiltration Over C2 ChannelThe implant POSTs stolen cards, merchant keys, and host secrets as JSON to the article's identified attacker-controlled C2 endpoints.T1082 · System Information DiscoveryDedicated analyzers collect host environment, system resource, cloud, and container information.T1140 · Deobfuscate/Decode Files or InformationGetDefaultEndpoint invokes EndpointObfuscator.Decode to recover the analytics endpoint at runtime.T1195.001 · Compromise Software Dependencies and Development ToolsMalicious NuGet packages enter applications through direct installation and poisoned dependencies, including transitively affected SIP packages.T1518 · Software DiscoveryThe implant inventories loaded assembly names, package references, and application project types.T1552.001 · Credentials In FilesConfigurationAnalyzer reads appsettings JSON files and connection strings, while the harvester probes service-account token paths and mounted secrets.T1552.005 · Cloud Instance Metadata APIThe cloud analyzer probes instance metadata, and the article reports collection of cloud IAM role credentials.
Malware
Vendors
BraintreeSocket’s AI scanner flagged a suspicious NuGet package masquerading as the official Braintree payment gateway client, with the first malicious version published on July 3, 2026. It was detected by Socket as potentialCloudflareis not registered infrastructure belonging to Shakepay (shakepay.com). Passive DNS resolution returns Cloudflare anycast addresses (104.21[.]89.51, 172.67[.]188.32), consistent with attacker-controlled origin hidingPayPalharvests host environment secrets upon assembly load. The package Braintree.Net copies the surface API of PayPal Braintree's legitimate Braintree SDK while routing stolen data to attacker-controlled infrastructure at
Products
.NET10 minutes after publication. Follow-on analysis by the Socket Threat Research team revealed a multi-stage .NET implant that intercepts live payment card data, exfiltrates Braintree merchant API keys and harvests hostBraintreeSocket’s AI scanner flagged a suspicious NuGet package masquerading as the official Braintree payment gateway client, with the first malicious version published on July 3, 2026. It was detected by Socket as potentialNuGetSocket’s AI scanner flagged a suspicious NuGet package masquerading as the official Braintree payment gateway client, with the first malicious version published on July 3, 2026. It was detected by Socket as potentialSipNetpkg:nuget/sipnet@12.8.4SipNet.OpenAI.Realtimepkg:nuget/sipnet.openai.realtime@12.8.3 (indirect, depending on sipnet)SIPSorceryBeyond Braintree.Net, the same braintree nuget.org account publishes a family of SIP/WebRTC packages that typosquat the popular SIPSorcery ecosystem, two of which route to the malicious DependencyInjector.Core harvester: