logo

Researchers uncover WebRTC skimmer bypassing traditional defenses

ID: 7315c60d-d28e-5902-a7f6-51fbe0e76412

STIX ID: report--7315c60d-d28e-5902-a7f6-51fbe0e76412

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Researchers uncovered a new payment-card skimmer that uses WebRTC DataChannels (DTLS-encrypted UDP) to fetch and exfiltrate malicious JavaScript, bypassing Content Security Policy and HTTP-based network detection; the skimmer exploits the PolyShell vulnerability in Magento/Adobe Commerce, has been actively scanned and used in the wild since March 19, 2026, and the report includes IoCs such as a hardcoded attacker IP and port.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.