logo

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

ID: 7926dfb0-d753-562f-ac67-29553d558b09

STIX ID: report--7926dfb0-d753-562f-ac67-29553d558b09

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2023-12-22

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Threat hunters identified a rogue WordPress plugin used in a Magecart campaign that creates hidden admin users, persists in mu-plugins, and injects JavaScript skimmers (including via WebSockets and fake checkout overlays) to exfiltrate credit card data from e-commerce sites; the report additionally references dozens of JS-sniffer families and a large crypto-drainer fraud operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.