JS Sniffer: E-commerce Data Theft Made Easy
ID: d6e2620a-a4e4-5ec7-80b3-ed420c913e5d
STIX ID: report--d6e2620a-a4e4-5ec7-80b3-ed420c913e5d
Feed Name: Volexity Blog
Volexity analyzes JS Sniffer, a JavaScript skimmer framework (version 3.3) used since 2017 to steal customer PII and payment-card data from compromised e-commerce sites—especially Magento—by injecting or loading malicious JS (often disguised as analytics) that captures form fields, encodes them in base64, and exfiltrates them via HTTP(S) GET requests to attacker-controlled servers. The report includes example captured data, admin panel and database details, regex parsing rules, IOCs (domains and IPs), and Suricata/Snort signatures, and recommends patching vulnerable e-commerce platforms and searching web logs for the provided indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
