logo

Meet the JS-Sniffers 4: CoffeMokko Family

ID: 72bec80d-591f-51cf-9535-abd8ad121d96

STIX ID: report--72bec80d-591f-51cf-9535-abd8ad121d96

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2019-04-26

Date Updated: 2026-04-27

...
...

**CoffeMokko JS-sniffers:** Group-IB’s analysis documents a long-running (since May 2017) JS-sniffer campaign that injects unique JavaScript on compromised Magento, OpenCart, WordPress, osCommerce and Shopify stores to harvest payment form fields and exfiltrate card data to attacker-controlled gates; the report details obfuscation algorithms, character-mapped Base64 encoding, infrastructure patterns (fake domains, /js or /src directories, gate scripts such as /path/savePayment/index.php and /tr/index.php), examples of decoded resources, and links to earlier Magecart/Group 1 activity suggesting tool or operator overlap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.