#alessandro.ricci
1 messages · Page 1 of 1 (latest)
Hello
Can you give me an example of what you are seeing?
An example request ID that is
And can you tell me what you mean by "suspicious" exactly?
We don't call in any case that endpoint, we always use only stripe pages to make our customer pay, also we see as a source Python/3.11 aiohttp/3.8.4 we don't use any python client
So this looks like an attempt to tokenize card information using your secret key. I can see it looks like you mostly use a plugin
Yep
Looks to me from a glance like somehow your secret key got leaked
yes we use the official plugin
So I'd recommend rolling your keys and updating your plugin with your new keys