WooCommerce Payment Skimmer Mimics Stripe to Steal Cards at Real Checkouts
ID: 8492c784-6103-563e-9dc0-878ed2404167
STIX ID: report--8492c784-6103-563e-9dc0-878ed2404167
Feed Name: securityonline.info
CloudSEK analysis details a WooCommerce payment skimmer that overlays a fake Stripe-styled payment form on legitimate checkouts to capture full card data and customer email; the skimmer stays dormant until a Stripe element is detected, mimics validation (Luhn, brand detection, expiry checks) to avoid user suspicion, encodes and exfiltrates stolen records, and commonly arrives via vulnerable plugins, weak admin credentials, or web shells — merchants should treat self-encoded checkout scripts as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
