logo

Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse

ID: 702045a7-4d89-5cb4-a632-53bb6f752641

STIX ID: report--702045a7-4d89-5cb4-a632-53bb6f752641

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-07-21

Author: Divya

...
...

Sansec uncovered a large-scale Magecart campaign infecting nearly 100 Magento stores by embedding a base64-encoded skimmer inside a 1×1 SVG onload handler; the skimmer intercepts checkout clicks to display a convincing fake “Secure Checkout” overlay, XOR-encrypts stolen card data with key "script" then base64-encodes it and exfiltrates to six attacker-controlled domains (all resolving to 23.137.249.67, IncogNet LLC AS40663). The report provides IOCs (domains, IP/AS, localStorage key _mgx_cv, payload markers), describes evasion techniques (inline SVG, double-encoded URLs, no-cors fetch/iframe fallback), and links initial access to the PolyShell vulnerability affecting unpatched Magento environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.