logo

Magecart Hack Injects JavaScript to Steal Online Payment Data

ID: 170874b6-dc61-5d32-a60c-f2b6e22cf75f

STIX ID: report--170874b6-dc61-5d32-a60c-f2b6e22cf75f

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-21

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A Magecart-style campaign is actively compromising e-commerce sites by injecting heavily obfuscated JavaScript (hosted on cc-analytics.com and related domains) into checkout pages to capture payment card and billing details and exfiltrate them via XMLHttpRequest to attacker-controlled servers (notably pstatics.com). Researchers traced the infrastructure to IP 45.61.136.141 and a portfolio of 30+ suspicious domains, documented the skimmer's input listeners and validation logic, and recommended detection controls such as monitoring unexpected script tags, network POSTs to external domains, subresource integrity, and payment form isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.