logo

Silent Push Exposes Magecart Network Operating Since Early 2022

ID: fbebd82d-a0ee-5dc8-88a3-589f6b9acde7

STIX ID: report--fbebd82d-a0ee-5dc8-88a3-589f6b9acde7

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-22

Author: Michael Vizard

...
...

Silent Push disclosed a long-running Magecart web‑skimming campaign that used domains such as cdn-cookie.com (hosted on ASN 209847) to deliver highly obfuscated JavaScript skimmers that exfiltrate credit card data from multiple major payment networks. Researchers identified ~600 lines of obfuscated JS, multiple infection instances dating back to January 2022, associated infrastructure, and recommended mitigations including Content Security Policy (CSP), PCI DSS adherence, and regular administrative checks to detect injections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.