logo

Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

ID: 9f891ce6-a01f-5800-bc6e-ee44fd99a134

STIX ID: report--9f891ce6-a01f-5800-bc6e-ee44fd99a134

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers have identified a global web skimming campaign using over 50 malicious scripts that inject fake payment forms and silently record keystrokes to harvest payment card data, credentials, and other PII. The attackers employ modular, localized payloads that target major payment gateways (Stripe, PayPal, Mollie, PagSeguro, OnePay, etc.), use deceptive domains (e.g., googlemanageranalytic.com, gtm-analyticsdn.com, jquery-stupify.com) to blend with legitimate libraries, and implement anti-forensics (hidden inputs, Luhn-valid junk cards) to enable prolonged, persistent data harvesting and account takeover. Organizations are advised to strengthen client-side protections, apply content security policies, and deploy real-time payment form monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.