Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores
ID: 12c6e685-e9de-5a18-835e-7b6cf08b1baa
STIX ID: report--12c6e685-e9de-5a18-835e-7b6cf08b1baa
Feed Name: GBHackers
HexMage is a live Magecart campaign compromising over 40 e-commerce storefronts across about 15 countries by injecting a fake Google Tag Manager-style JavaScript loader into checkout pages; the loader uses ethers.js to query attacker-controlled smart contracts on the Sepolia testnet (EtherHiding) which return disposable payload hostnames, allowing flexible, blockchain-backed delivery of JavaScript skimmers that steal payment-card details and exfiltrate them while avoiding easy static detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
