Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.

Dark Reading Staff, Dark Reading

June 22, 2022

1 Min Read
Hands typing on laptop shopping with online cart
Source: Skorzewiak via Alamy Stock Photo

Although observed Magecart skimmer attacks have been less frequently reported in recent months, analysts have discovered fresh infrastructure they were able to trace to malicious domains behind an ongoing campaign.

The Malwarebytes Labs team connected the skimmers to activity dating back to May 2020. 

The attackers hid the skimmer behind three JavaScript library themes, the report said: 

  • hal-data[.]org/gre/code.js (Angular JS)

  • hal-data[.]org/data/ (Logger)

  • js.g-livestatic[.]com/theme/main.js (Modernizr)

The team added that a recent drop in Magecart activity could be because many threat actors may be pivoting from stealing credit-card numbers to more profitable targets.

"Crypto wallets and similar digital assets are extremely valuable and there is no doubt that clever schemes to rob those are in place beyond phishing for them," the team wrote.

But worryingly, the disappearance of Magecart from the radar could also be because the attacks have moved server-side and become harder to detect with simple scanners, the analysts said. 

"Perhaps we have been too focused on the Magento CMS, or our crawlers and sandboxes are being detected because of various checks including at the network level," the team said about waning detections of Magecart skimmer attacks.

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights