A sophisticated new malvertising scheme has emerged, transforming trusted e-commerce websites into phishing traps without the knowledge of site owners or advertisers.
Cybercriminals are exploiting integrations with Google APIs, specifically through JSONP (JSON with Padding) calls, to inject malicious scripts into legitimate online stores.
These scripts operate covertly, redirecting unsuspecting shoppers to fraudulent payment pages where they are tricked into disclosing sensitive credit card information under the guise of paying trusted merchants.
Unlike traditional malvertising campaigns that rely on suspicious ads or overt redirects, this attack leverages the credibility of high-quality sites and clean ad placements, making it particularly insidious.
Shoppers clicking on legitimate advertisements are led to real storefronts, only to encounter invisible threats hidden beneath the surface.
A notable case involved Ray-Ban’s Indian store (india.ray-ban.com), where attackers compromised the site’s backend, turning a trusted brand into an unwitting phishing platform.
This double-edged strategy allows attackers to hijack brand credibility while exploiting the victimized companies’ marketing efforts to drive traffic to their scams all without investing in distribution.
Exploiting Legitimate E-Commerce Sites for Phishing
The core of this attack lies in the exploitation of JSONP, a now-outdated technique used to bypass the browser’s same-origin policy by loading data from external domains via script tags.

JSONP responses execute immediately upon loading, offering no control over the content and posing significant security risks, including susceptibility to cross-site scripting (XSS) attacks.
If an attacker compromises an API endpoint, they can inject malicious JavaScript that executes unchecked.
Complicating matters further, even robust Content Security Policy (CSP) configurations often fail to block these payloads because trusted domains like Google’s are explicitly allowed.
Vulnerable Google APIs, such as translate.googleapis.com, accounts.google.com, and www.youtube.com, have been identified as vectors for delivering these malicious scripts.
This vulnerability, initially uncovered by Source Defense’s research team and reported to Google on November 19, 2024 (Issue ID: 379818473), enables attackers to bypass conventional defenses and target users on legitimate platforms.
JSONP Vulnerabilities in Google APIs
The attack chain often culminates in redirects to fake payment pages hosted on malicious domains like montina[.]it or premium[.]vn, as evidenced by captured network traffic from compromised sites.

Many affected e-commerce platforms, including those running Adobe Commerce and Magento, have shown evidence of multiple injected scripts, amplifying the risk to users.
Despite the threat being disclosed to Google in November 2024, several compromised websites remain active, continuing to expose users to phishing risks.
The persistence of this attack, though currently small in scale, is alarming due to its sophistication and ability to weaponize trusted infrastructure.
Beyond phishing, attackers can exploit these vulnerabilities for auto-redirect attacks, silently funneling users to scam pages without any interaction, which severely erodes user trust and damages publisher reputation.
The case of india.ray-ban.com, previously compromised via the CosmicSting vulnerability, highlights the recurring nature of such threats, even though the site has since been remediated.
As cybercriminals continue to exploit trusted domains like Google’s to deliver malicious payloads, constant vigilance and proactive monitoring for suspicious script injections are critical.
This evolving threat underscores the need for enhanced security measures to protect users and preserve the integrity of legitimate online platforms in the face of increasingly covert attacks.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!





