logo

Hackers use pixel-large SVG trick to hide credit card stealer

ID: 2519cca3-c0f4-57c5-9e2b-186c0ae80119

STIX ID: report--2519cca3-c0f4-57c5-9e2b-186c0ae80119

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-04-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sansec discovered a large campaign targeting nearly 100 Magento e-commerce stores in which attackers likely exploited the PolyShell unauthenticated code-execution vulnerability to inject a 1x1-pixel SVG containing a base64-encoded onload payload that acts as a credit-card skimmer; the skimmer displays a fake checkout overlay, validates card data (Luhn), and exfiltrates XOR-encrypted/base64 JSON to attacker-controlled domains (six exfiltration domains hosted at IncogNet, IP 23.137.249.67). Sansec published detection and mitigation advice (search for hidden SVG onload with atob(), check localStorage key _mgx_cv, block /fb_metrics.php and the listed IP/domains) and notes Adobe has not yet released a production fix for PolyShell.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.