logo

Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages

ID: 3e0265b3-2c60-50ef-aa4a-10676a6766c6

STIX ID: report--3e0265b3-2c60-50ef-aa4a-10676a6766c6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

Sansec identified a large Magecart campaign affecting 99 Magento stores that uses a novel SVG onload evasion technique to inject an inline, base64-encoded skimmer. The skimmer intercepts checkout clicks (useCapture), displays a convincing fake "Secure Checkout" overlay to collect card data, encrypts the data with an XOR cipher (key: "script") and base64, then exfiltrates it to six attacker-controlled domains (fb_metrics.php endpoints) resolving to IP 23.137.249.67; the likely initial vector is the PolyShell vulnerability and indicators include suspicious <svg> onload attributes, a localStorage key (key_mgx_cv), and fetch() POST no-cors exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.