{"id":9567,"date":"2025-12-31T10:01:25","date_gmt":"2025-12-31T10:01:25","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/31\/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows\/"},"modified":"2025-12-31T10:01:25","modified_gmt":"2025-12-31T10:01:25","slug":"massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/31\/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows\/","title":{"rendered":"Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows"},"content":{"rendered":"<p>    Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. <\/p>\n<p>Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. <\/p>\n<p>The attack demonstrates a significant evolution in how cybercriminals target e-commerce platforms, moving beyond simple credit card theft to stealing full customer identities.<\/p>\n<p>The campaign employs modular payloads designed for specific payment processors. Attackers have created localized variations that specifically target Stripe, Mollie, PagSeguro, OnePay, PayPal, and other major payment gateways. <\/p>\n<p>This customized approach allows the malware to blend seamlessly with legitimate payment interfaces, making detection significantly harder for both security teams and customers completing transactions.<\/p>\n<p>Source Defense Research analysts <a href=\"https:\/\/x.com\/sdcyberresearch\/status\/2005621112898548175\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware infrastructure, uncovering a sophisticated network of domain names used to distribute and control the attack. <\/p>\n<p>Domains such as googlemanageranalytic.com, gtm-analyticsdn.com, and jquery-stupify.com were crafted to appear legitimate, often mimicking popular libraries and analytics services that websites normally load. <\/p>\n<p>This deception allows the malicious scripts to execute without raising immediate suspicion.<\/p>\n<figure class=\"wp-block-embed aligncenter is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f6a8.png?ssl=1\" alt=\"\ud83d\udea8\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">Massive <a href=\"https:\/\/twitter.com\/hashtag\/Magecart?src=hash&amp;ref_src=twsrc%5Etfw\">#Magecart<\/a> campaign uncovered<br \/>An over 50-script global operation hijacking checkout and account creation flows. <\/p>\n<p>Modular, localized payloads target Stripe, Mollie, PagSeguro, OnePay, PayPal &amp; more.<br \/>Uses fake payment forms, phishing iframes, and silent <a href=\"https:\/\/twitter.com\/hashtag\/skimming?src=hash&amp;ref_src=twsrc%5Etfw\">#skimming<\/a>, plus\u2026 <a href=\"https:\/\/t.co\/9wlHk5OmDH\">pic.twitter.com\/9wlHk5OmDH<\/a><\/p>\n<p>\u2014 Source Defense Research (@sdcyberresearch) <a href=\"https:\/\/twitter.com\/sdcyberresearch\/status\/2005621112898548175?ref_src=twsrc%5Etfw\">December 29, 2025<\/a>\n<\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div>\n<\/div>\n<\/figure>\n<p>The attack operates through multiple infection vectors that make it exceptionally dangerous. <a href=\"https:\/\/cybersecuritynews.com\/researchers-details-masking-malicious-scripts\/\" target=\"_blank\" rel=\"noreferrer noopener\">Malicious scripts<\/a> inject fake payment forms directly into websites, creating convincing phishing interfaces that capture customer data. <\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-campaign\"><strong>The campaign<\/strong><\/h2>\n<p>The campaign also deploys silent skimming techniques, quietly recording information as users type. <\/p>\n<p>Additionally, the scripts implement anti-forensics measures including hidden form inputs and Luhn-valid junk card generation, which complicates incident response and analysis efforts.<\/p>\n<p>What sets this campaign apart is its expanded scope beyond payment card details. The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> actively harvests user credentials, personally identifiable information, and email addresses. <\/p>\n<p>This comprehensive data collection enables attackers to conduct account takeover attacks and establish persistent access through rogue administrator accounts. The threat has effectively evolved from card-specific skimming into a full identity compromise operation.<\/p>\n<p>The campaign reveals how web <a href=\"https:\/\/cybersecuritynews.com\/web-skimming-attack-uses-legacy-stripe-api\/\" target=\"_blank\" rel=\"noreferrer noopener\">skimming<\/a> has matured into a sophisticated, long-term persistence mechanism. <\/p>\n<p>By stealing credentials and establishing admin access, attackers can maintain control over compromised websites for extended periods, continuously harvesting data from multiple transaction flows. <\/p>\n<p>Organizations running e-commerce platforms must strengthen client-side security, implement content security policies, and deploy real-time payment form monitoring to detect and block such malicious injections before they reach customers.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/massive-magecart-with-50-malicious-scripts\/\">Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/massive-magecart-with-50-malicious-scripts\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack demonstrates a significant [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9567","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9567"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9567"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9567\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9567"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9567"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9567"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}