Cyber Security News

New Magecart Attack Inject Malicious JavaScript to Skim Payment Data

A new Magecart-style campaign has emerged, targeting online shoppers through malicious JavaScript code designed to steal payment information directly from ecommerce websites.

The attack works by injecting hidden scripts into compromised shopping sites, allowing attackers to intercept sensitive data when customers enter their credit card details during checkout.

Magecart attacks represent a significant threat to online retailers and their customers. These campaigns have evolved over several years, with cybercriminals continuously refining their methods to avoid detection.

The latest variant demonstrates sophisticated obfuscation techniques, making it harder for security teams to identify and block the malicious code before it damages customer trust and business operations.

Security analyst Himanshu Anand identified this particular campaign through open-source threat intelligence. He traced the attack back to a primary domain, cc-analytics.com, which was hosting the malicious JavaScript file.

The discovery revealed a coordinated effort by threat actors to deploy similar payloads across multiple ecommerce platforms, suggesting a widespread campaign affecting numerous online businesses and their customers.

The stolen data gets sent to attacker-controlled servers where criminals harvest the payment information for resale or fraudulent use.

This campaign shows how attackers exploit trusted ecommerce environments to target customers at their most vulnerable moment—when making an online purchase.

How the Attack Infection Mechanism Works?

The malicious JavaScript operates through a multi-stage process that remains hidden from customers and website administrators.

When an unsuspecting shopper visits a compromised ecommerce site, the attacker’s code quietly loads in the background through a simple script tag injected into the webpage’s HTML code.

Revealed injections (Source – Himanshu Anand)

Once active, the script targets specific form fields where customers enter sensitive information. It hooks into checkout buttons and payment form elements, monitoring user activity for signs of payment data entry.

When a customer types their credit card number and billing address, the JavaScript captures this information in real-time before the legitimate payment gateway even receives it.

The theft happens instantly through an automated data exfiltration function. The captured payment details get bundled into a request and sent to attacker infrastructure, specifically to domains like pstatics.com.

By the time a customer completes their purchase, their credit card information has already been harvested and sent to the criminals behind the campaign.

What makes this attack particularly dangerous is its invisibility. The JavaScript runs silently without triggering browser security warnings or leaving obvious signs of compromise.

The obfuscation techniques used render the code unreadable to automated security tools, enabling it to persist on compromised websites for extended periods while continuously stealing data from unsuspecting customers.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago