logo

Update on JavaScript Skimmer Enhancements

ID: 1be02e7d-985e-53d4-a2f1-40217e4027bb

STIX ID: report--1be02e7d-985e-53d4-a2f1-40217e4027bb

Feed Name: Zscaler Security Research Blog

Threat Score
72/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documents an active card-skimming campaign (Magecart-style) targeting e-commerce platforms (Magento, BigCommerce, etc.) where attackers inject obfuscated JavaScript and even CSS-based payloads into CDN- and S3-hosted assets to capture checkout/payment data, use iframe overlays for fake payment fields, encode stolen data in Base64 and exfiltrate it via GET requests to C2 servers; the report includes technical analysis, observed enhancements, and a comprehensive IoC list.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.