logo

“Magecart” Strikes Again: Long-Running Web Skimming Campaign Targets Global Payment Networks

ID: 782db2a3-7d2a-562a-bfea-f38bec8267fb

STIX ID: report--782db2a3-7d2a-562a-bfea-f38bec8267fb

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-15

Date Updated: 2026-04-23

Author: Ddos

...
...

A long‑running Magecart web‑skimming campaign (active since Jan 2022) has been compromising e‑commerce sites using WooCommerce/Stripe to inject malicious JavaScript that replaces legitimate Stripe payment forms with fake, localized iframes to harvest and exfiltrate encrypted credit card details; the malware uses MutationObserver and a wpadminbar self‑destruct check to evade detection and uses resilient (bulletproof) hosting for its C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.