{"id":9865,"date":"2026-01-14T10:04:03","date_gmt":"2026-01-14T10:04:03","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/14\/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages\/"},"modified":"2026-01-14T10:04:03","modified_gmt":"2026-01-14T10:04:03","slug":"new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/14\/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages\/","title":{"rendered":"New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages"},"content":{"rendered":"<p>    New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. <\/p>\n<p>The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail security. <\/p>\n<p>Threat researchers have documented extensive infrastructure associated with this long-running campaign, which has operated since at least early 2022. <\/p>\n<p>The malicious network targets major payment providers including American Express, Diners Club, Discover, Mastercard, JCB, and UnionPay, potentially affecting millions of customers globally.<\/p>\n<p>The attack operates through JavaScript injection, where malicious code embeds itself into legitimate e-commerce websites without triggering obvious security alerts. <\/p>\n<p>Once injected, the code remains dormant until visitors reach the checkout page, at which point it initiates its credential-stealing payload. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgeUowUmdTyj_Vu_xVnQdyLOSD_F7pJGgN35VBQ2ROgI0D9v5epg1o4qObQ8b-ybKrTrGs36QnLvQv5sI9pB5qVSUPtx_f-Wo5ZuF2ZPYdcdjtvJ0afK9DxG3akwN2xxMLksSUfNEfujamV8ewo6dK8k0cxGeCyW6wo9xVeA1Iv6_AIHXvlhJF7eRMlMoo\/s16000\/Chronicling%2520steps%2520in%2520the%2520web%2520skimmer%2520process%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"Chronicling steps in the web skimmer process (Source - Silent Push)\"><figcaption class=\"wp-element-caption\">Chronicling steps in the web skimmer process (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>The infrastructure relies on compromised domains and bulletproof hosting providers to maintain persistence and avoid detection. <\/p>\n<p>Silent Push analysts and researchers <a href=\"https:\/\/www.silentpush.com\/blog\/magecart\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the attackers have advanced knowledge of WordPress internals, leveraging lesser-known features like wp_enqueue_scripts action hooks to integrate malicious scripts into the website rendering process.<\/p>\n<p>The technical sophistication lies in how the malware creates a convincing facade during the payment process. <\/p>\n<p>The skimmer establishes a MutationObserver to <a href=\"https:\/\/cybersecuritynews.com\/why-you-need-to-monitor-legitimate-bot-trafficgic-visibility-gap-long-term-bot-insights\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitor<\/a> webpage changes in real-time, ensuring continuous monitoring of the payment form environment. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIGHx8blTnpboZ0ZdDfo9kGPRyv-3zGDY6WBYnldgKYwcacjFEvGeskEo461OD5m8AM24Agh0uFLtLd8UOso4iQ4cgx9QeMoaKNjg1vYNl_dx5wn764aop5D89fu99ZLGCNoXrIfyfGZzj7xdZLU-UckvNq15wfxd_qwoThyzilplQs0kksln1W3R9Jyo\/s16000\/Malicious%2520file%2520callout%2520on%2520the%2520checkout%2520page%2520for%2520colunexshop%255B.%255Dcom%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"Malicious file callout on the checkout page for colunexshop[.]com (Source - Silent Push)\"><figcaption class=\"wp-element-caption\">Malicious file callout on the checkout page for colunexshop[.]com (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>It then hides the legitimate Stripe payment form and injects a nearly identical <a href=\"https:\/\/cybersecuritynews.com\/fake-fortinet-sites\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake<\/a> form that captures card numbers, expiration dates, CVV codes, and billing information. <\/p>\n<p>The fake form includes brand detection logic that recognizes card types and displays corresponding brand images, reinforcing legitimacy to victims.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-sophisticated-data-exfiltration-mechanism\"><strong>Sophisticated Data Exfiltration Mechanism<\/strong><\/h2>\n<p>The data collection process captures more than payment details. The malware monitors every input field on the checkout page, harvesting names, addresses, and email information. <\/p>\n<p>Once victims complete the form and click the Place Order button, the <a href=\"https:\/\/cybersecuritynews.com\/silent-skimmer-shopping-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">skimmer<\/a> compiles all collected data into a structured object, applies XOR encryption with a hardcoded key of 777, and encodes it in Base64 format. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgffyZnEf6mXOWz__iuYy6CAepA53NljJkMo83hD_4FaLNAskIb3xwmdjbNi8sOHztRDgMprzRF7vKdLYpoKeW7ahUogowaapThqgplEJENpgXB0sZsWHiqxNW89p3GXi5gAVCf9XKflhOmFcCqqzUo9L6TLL0un5mPMSl5uUzYWEGQU6TShyRdT1GDUPs\/s16000\/Improper%2520use%2520of%2520code%2520results%2520in%2520a%2520visible%2520bug%2520on%2520the%2520infected%2520website%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Improper use of code results in a visible bug on the infected website (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>The encrypted payload then transmits via HTTP POST request to <a href=\"https:\/\/cybersecuritynews.com\/cl0p-ransomware-data-exfiltration-vulnerable\/\" target=\"_blank\" rel=\"noreferrer noopener\">exfiltration<\/a> servers located on compromised infrastructure.<\/p>\n<p>The attack exploits user psychology by displaying payment errors after form submission, misleading victims into believing they entered incorrect information. <\/p>\n<p>Unsuspecting customers typically re-enter credentials into the legitimate form, completing their purchase successfully while remaining unaware their data was already stolen. <\/p>\n<p>This psychological manipulation dramatically increases attack success rates by avoiding suspicion. <\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> includes evasion tactics that detect WordPress administrator status through the admin bar element and automatically disables itself when administrators view the site, significantly extending the campaign\u2019s operational lifespan. <\/p>\n<p>Security researchers predict this multi-year threat will continue targeting vulnerable online stores throughout 2026.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-magecart-attack-steals-customers-credit-cards\/\">New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-magecart-attack-steals-customers-credit-cards\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9865","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9865"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9865"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9865\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9865"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9865"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9865"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}