Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse
ID: 702045a7-4d89-5cb4-a632-53bb6f752641
STIX ID: report--702045a7-4d89-5cb4-a632-53bb6f752641
Feed Name: GBHackers
Sansec uncovered a large-scale Magecart campaign infecting nearly 100 Magento stores by embedding a base64-encoded skimmer inside a 1×1 SVG onload handler; the skimmer intercepts checkout clicks to display a convincing fake “Secure Checkout” overlay, XOR-encrypts stolen card data with key "script" then base64-encodes it and exfiltrates to six attacker-controlled domains (all resolving to 23.137.249.67, IncogNet LLC AS40663). The report provides IOCs (domains, IP/AS, localStorage key _mgx_cv, payload markers), describes evasion techniques (inline SVG, double-encoded URLs, no-cors fetch/iframe fallback), and links initial access to the PolyShell vulnerability affecting unpatched Magento environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
