logo

Magecart Attackers Pioneer Persistent E-Commerce Backdoor

ID: 8dcc38b0-f66a-54f1-b48f-909d32ee3135

STIX ID: report--8dcc38b0-f66a-54f1-b48f-909d32ee3135

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-04-05

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Sansec researchers observed Magecart operators exploiting a critical Magento command injection (CVE-2024-20720, CVSS 9.1) that allows attackers to store XML layout templates as persistent backdoors in the layout_update table; the backdoor executes on /checkout/cart and injects a Stripe payment skimmer that captures and exfiltrates payment data. Adobe has patched the issue—e-tailers should upgrade to 2.4.6-p4, 2.4.5-p6, or 2.4.4-p7 to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.