Hackers use pixel-large SVG trick to hide credit card stealer
ID: 2519cca3-c0f4-57c5-9e2b-186c0ae80119
STIX ID: report--2519cca3-c0f4-57c5-9e2b-186c0ae80119
Feed Name: Bleeping Computer
Sansec discovered a large campaign targeting nearly 100 Magento e-commerce stores in which attackers likely exploited the PolyShell unauthenticated code-execution vulnerability to inject a 1x1-pixel SVG containing a base64-encoded onload payload that acts as a credit-card skimmer; the skimmer displays a fake checkout overlay, validates card data (Luhn), and exfiltrates XOR-encrypted/base64 JSON to attacker-controlled domains (six exfiltration domains hosted at IncogNet, IP 23.137.249.67). Sansec published detection and mitigation advice (search for hidden SVG onload with atob(), check localStorage key _mgx_cv, block /fb_metrics.php and the listed IP/domains) and notes Adobe has not yet released a production fix for PolyShell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
