logo

Magecart Hackers Abuse Ethereum Smart Contracts to Steal Card Data From 40+ Online Stores

ID: 12c6e685-e9de-5a18-835e-7b6cf08b1baa

STIX ID: report--12c6e685-e9de-5a18-835e-7b6cf08b1baa

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-31

Date Updated: 2026-09-01

Author: Mayura Kathir

...
...

HexMage is a live Magecart campaign compromising over 40 e-commerce storefronts across about 15 countries by injecting a fake Google Tag Manager-style JavaScript loader into checkout pages; the loader uses ethers.js to query attacker-controlled smart contracts on the Sepolia testnet (EtherHiding) which return disposable payload hostnames, allowing flexible, blockchain-backed delivery of JavaScript skimmers that steal payment-card details and exfiltrate them while avoiding easy static detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.