logo

Lost in the Ether: Unravelling a JavaScript Card Skimming Campaign | Trinity Cyber

ID: b9053c55-2c5a-5087-8fc8-34a29536aab0

STIX ID: report--b9053c55-2c5a-5087-8fc8-34a29536aab0

Feed Name: Trinity Cyber Blog

Threat Score
70/100

Date Published: 2026-01-27

Date Updated: 2026-05-01

Author: Trinity Cyber

...
...

This report explains an active and sophisticated payment‑skimming campaign dubbed “EtherHiding” in which attackers inject a small obfuscated JavaScript loader into legitimate e‑commerce sites, retrieve additional obfuscated loaders from smart contracts on the Binance Smart Chain, perform anti‑analysis checks, and stream a Magecart‑style skimmer over WebSockets to capture and exfiltrate credit card data and credentials; the use of blockchain hosting, heavy obfuscation, and in‑browser operation increases persistence, evasion, and takedown resistance, and Trinity Cyber recommends Full Content Inspection to block such threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.