Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
HackerOne Mandates ID Verification for Bug Bounty Submissions
August 1, 2026
Arch Linux Disables AUR Package Takeovers After Malicious Commits
August 1, 2026
Keycloak CVE-2024-3700 Exposes User Data Across Admin Boundaries
July 31, 2026
Home/Threats/Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows
Threats

Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows

Magecart Hijacks Checkout & Accounts with Massive Malicious Heads up, everyone. A massive web skimming operation has just popped up across the internet. And get this: it’s hitting online...

David kimber
David kimber
January 2, 2026 2 Min Read
112 0

Magecart Hijacks Checkout & Accounts with Massive Malicious

Heads up, everyone. A massive web skimming operation has just popped up across the internet. And get this: it’s hitting online shoppers and account holders with a scope we really haven’t seen before. Seriously, it’s unprecedented.

Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes.

The attack demonstrates a significant evolution in how cybercriminals target e-commerce platforms, moving beyond simple credit card theft to stealing full customer identities.

The campaign employs modular payloads designed for specific payment processors. Attackers have created localized variations that specifically target Stripe, Mollie, PagSeguro, OnePay, PayPal, and other major payment gateways.

This customized approach allows the malware to blend seamlessly with legitimate payment interfaces, making detection significantly harder for both security teams and customers completing transactions.

Source Defense Research analysts identified the malware infrastructure, uncovering a sophisticated network of domain names used to distribute and control the attack.

Domains such as googlemanageranalytic.com, gtm-analyticsdn.com, and jquery-stupify.com were crafted to appear legitimate, often mimicking popular libraries and analytics services that websites normally load.

This deception allows the malicious scripts to execute without raising immediate suspicion.

🚨Massive #Magecart campaign uncovered
An over 50-script global operation hijacking checkout and account creation flows.

Modular, localized payloads target Stripe, Mollie, PagSeguro, OnePay, PayPal & more.
Uses fake payment forms, phishing iframes, and silent #skimming, plus… pic.twitter.com/9wlHk5OmDH

— Source Defense Research (@sdcyberresearch) December 29, 2025

The attack operates through multiple infection vectors that make it exceptionally dangerous. Malicious scripts inject fake payment forms directly into websites, creating convincing phishing interfaces that capture customer data.

The campaign

The campaign also deploys silent skimming techniques, quietly recording information as users type.

Additionally, the scripts implement anti-forensics measures including hidden form inputs and Luhn-valid junk card generation, which complicates incident response and analysis efforts.

What sets this campaign apart is its expanded scope beyond payment card details. The malware actively harvests user credentials, personally identifiable information, and email addresses.

This comprehensive data collection enables attackers to conduct account takeover attacks and establish persistent access through rogue administrator accounts. The threat has effectively evolved from card-specific skimming into a full identity compromise operation.

The campaign reveals how web skimming has matured into a sophisticated, long-term persistence mechanism.

By stealing credentials and establishing admin access, attackers can maintain control over compromised websites for extended periods, continuously harvesting data from multiple transaction flows.

Organizations running e-commerce platforms must strengthen client-side security, implement content security policies, and deploy real-time payment form monitoring to detect and block such malicious injections before they reach customers.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AptAttackDefenseMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

HPE Alerts Employees of Data Breach After Russian Cyberattack on Office 365

Next Post

INTERPOL Warns of Sharp Rise in Cyber Attacks Targeting Western and Eastern Africa

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
FBI Warns North Korean IT Workers Exploit Stolen Identities
July 31, 2026
Google AI Agents Find and Fix 1,072 Chrome Vulnerabilities
July 31, 2026
North Korean EtherHiding Targets Crypto Wallets and Developer Credentials
July 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us