logo

Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Friday

ID: 2cff4da8-4094-51d4-885c-6823f688d0b7

STIX ID: report--2cff4da8-4094-51d4-885c-6823f688d0b7

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-11-27

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Security researchers at Sucuri identified a Magento-targeting card‑skimming campaign that injects obfuscated JavaScript into checkout pages (triggering on URLs containing "checkout" but excluding "cart") to capture credit card and billing data, then JSON-encodes, XOR-encrypts (key: "script"), Base64-encodes, and beacons the data to attacker-controlled domains such as staticfonts.com and dynamicopenfonts.app; the malware also collects additional customer data via Magento APIs. Sucuri recommends regular security audits, deployment of a robust WAF, timely patching of plugins/themes, strong credentials, and file integrity monitoring to detect and prevent such skimmers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.