logo

Hackers Exploit Magento Bug to Steal Payment Data from E-commerce Websites

ID: 5f8b33e3-3eb4-5ce9-b19c-d89b1dc0ef5a

STIX ID: report--5f8b33e3-3eb4-5ce9-b19c-d89b1dc0ef5a

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-04-06

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Attackers are actively exploiting CVE-2024-20720 (CVSS 9.1) in Magento to inject a persistent layout-template backdoor that executes system commands via the Magento layout parser and the beberlei/assert package; the injected code uses sed to install a Stripe payment skimmer that captures and exfiltrates payment card data, executing on requests to the checkout cart. Adobe released fixes on Feb 13, 2024, and security vendor Sansec reported the technique and observed skimmer delivery; the report also references prior criminal activity and arrests tied to payment-card skimming operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.