Cyber Security News

Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope.

Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes.

The attack demonstrates a significant evolution in how cybercriminals target e-commerce platforms, moving beyond simple credit card theft to stealing full customer identities.

The campaign employs modular payloads designed for specific payment processors. Attackers have created localized variations that specifically target Stripe, Mollie, PagSeguro, OnePay, PayPal, and other major payment gateways.

This customized approach allows the malware to blend seamlessly with legitimate payment interfaces, making detection significantly harder for both security teams and customers completing transactions.

Source Defense Research analysts identified the malware infrastructure, uncovering a sophisticated network of domain names used to distribute and control the attack.

Domains such as googlemanageranalytic.com, gtm-analyticsdn.com, and jquery-stupify.com were crafted to appear legitimate, often mimicking popular libraries and analytics services that websites normally load.

This deception allows the malicious scripts to execute without raising immediate suspicion.

The attack operates through multiple infection vectors that make it exceptionally dangerous. Malicious scripts inject fake payment forms directly into websites, creating convincing phishing interfaces that capture customer data.

The campaign

The campaign also deploys silent skimming techniques, quietly recording information as users type.

Additionally, the scripts implement anti-forensics measures including hidden form inputs and Luhn-valid junk card generation, which complicates incident response and analysis efforts.

What sets this campaign apart is its expanded scope beyond payment card details. The malware actively harvests user credentials, personally identifiable information, and email addresses.

This comprehensive data collection enables attackers to conduct account takeover attacks and establish persistent access through rogue administrator accounts. The threat has effectively evolved from card-specific skimming into a full identity compromise operation.

The campaign reveals how web skimming has matured into a sophisticated, long-term persistence mechanism.

By stealing credentials and establishing admin access, attackers can maintain control over compromised websites for extended periods, continuously harvesting data from multiple transaction flows.

Organizations running e-commerce platforms must strengthen client-side security, implement content security policies, and deploy real-time payment form monitoring to detect and block such malicious injections before they reach customers.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago