logo

WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

ID: 8ee1d98d-c6ab-5825-bf59-dfd19f6320c0

STIX ID: report--8ee1d98d-c6ab-5825-bf59-dfd19f6320c0

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Sansec researchers found a new payment-card skimmer targeting Magento stores by exploiting the PolyShell vulnerability to upload executables and achieve code execution; the skimmer establishes a WebRTC DataChannel to a hard-coded IP (202.181.177.177) on UDP port 3479 to retrieve JavaScript payloads and exfiltrate stolen payment data, bypassing Content Security Policy and HTTP-based inspection. Adobe released a beta fix (2.4.9-beta1) on March 10, 2026, but many production stores remain vulnerable and under mass exploitation; recommended mitigations include blocking access to pub/media/custom_options/ and scanning for web shells and backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.