Magecart Hack Injects JavaScript to Steal Online Payment Data
ID: 170874b6-dc61-5d32-a60c-f2b6e22cf75f
STIX ID: report--170874b6-dc61-5d32-a60c-f2b6e22cf75f
Feed Name: GBHackers
A Magecart-style campaign is actively compromising e-commerce sites by injecting heavily obfuscated JavaScript (hosted on cc-analytics.com and related domains) into checkout pages to capture payment card and billing details and exfiltrate them via XMLHttpRequest to attacker-controlled servers (notably pstatics.com). Researchers traced the infrastructure to IP 45.61.136.141 and a portfolio of 30+ suspicious domains, documented the skimmer's input listeners and validation logic, and recommended detection controls such as monitoring unexpected script tags, network POSTs to external domains, subresource integrity, and payment form isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
