Green Bay Packers' Online Pro Shop Sacked by Payment Skimmer
ID: fbb34a50-46be-5f2e-b925-97fd991379bb
STIX ID: report--fbb34a50-46be-5f2e-b925-97fd991379bb
Feed Name: Dark Reading
Date Published: 2025-01-08
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
A Magecart-style payment-card skimmer was discovered on the Green Bay Packers Pro Shop e-commerce site; attackers injected a script (https://js-stats.com/getInjector) that exfiltrated checkout fields by abusing a JSONP callback and YouTube oEmbed to bypass the site's CSP. The skimmer was active in two windows (Sept 23–24 and Oct 3–23, 2024), exposed full payment card data plus names, addresses and emails for approximately 8,514 customers, and was served via a third-party hosted store.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
