logo

Magecart hits again

ID: 48e4cd1d-6906-5bf9-a8b8-26d17252fd55

STIX ID: report--48e4cd1d-6906-5bf9-a8b8-26d17252fd55

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes ongoing Magecart web-skimming campaigns targeting online shopping sites: attackers inject JavaScript that captures PII and payment information before form submission and exfiltrates data (Base64-encoded) via GET requests to attacker-controlled gates. Two main cycles are described—skimmers loaded from other compromised sites and from newly registered domains—and the report includes common skimmer URL patterns, examples of reused skimmer file locations, and a list of malicious domains and sample paths to support detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.