logo

Magecart Strikes Again: Newegg in the Crosshairs

ID: 29e92092-ddeb-5b9b-9abd-d315c314c962

STIX ID: report--29e92092-ddeb-5b9b-9abd-d315c314c962

Feed Name: Volexity Blog

Threat Score
75/100

Date Published: 2018-09-19

Date Updated: 2026-05-01

...
...

Volexity and RiskIQ investigated a Magecart campaign that injected a small JavaScript skimmer into Newegg's checkout page (secure.newegg.com) to capture customers' payment details and POST them to a malicious domain (neweggstats.com). The domain and SSL certificate were registered on August 13, 2018, attacks were observed starting August 16, and the code was removed on September 18, 2018; the report includes the malicious script behavior and network indicators (neweggstats.com, 217.23.4.11, /GlobalData/).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.