logo

Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker

ID: b67182f8-d8bd-54a9-bc1e-d014d9e0b6f0

STIX ID: report--b67182f8-d8bd-54a9-bc1e-d014d9e0b6f0

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-04-12

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers observed MageCart-style credit card skimmers concealed as fake Meta Pixel tracker scripts and injected via custom script editors in WordPress plugins and Magento admin panels. The malicious script replaces references to connect.facebook.net with a compromised domain (b-connected.com) to load fbevents.js, which detects checkout pages and serves a fraudulent overlay to capture card details, exfiltrating them to another compromised site (www.donjuguetes.es). Similar Magento Shoplift variants use obfuscated JavaScript and WSS to load skimmers, targeting e-commerce sites built on WordPress and Magento and evading scanners by activating only on checkout flows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.