Monday, March 10, 2025
Homecyber securityVisa Warns of JavaScript Skimmer Baka that Steals Payment Card Data

Visa Warns of JavaScript Skimmer Baka that Steals Payment Card Data

Published on

SIEM as a Service

Follow Us on Google News

Visa warns of a new e-commerce skimmer dubbed Baka that loads malware dynamically to avoid static malware scanners and unique encryption to obfuscate the malicious code for every client.

Visa Payment Fraud Disruption (PFD) observed this skimmer across several merchant websites across multiple global regions.

Baka JavaScript Skimmer

PFD observed that seven C2 servers hosting the Baka skimming kit, the skimmer includes features that are common for an e-commerce skimmer such as data exfiltration from the target fields.

Based on its advanced design Baka believed to be created by a skilled developer, the most compelling features of the skimmer is it’s unique loader and obfuscation method.

The skimmer variant is designed to remove itself from memory when it detects any possibility of dynamic analysis with developer tools, this method is to avoid detection and analysis.

The Baka loader script works dynamically by adding a script tag to the current page that loads the remote JavaScript file.

When the user reaches the checkout page the loader executes the malicious skimming code, then it decrypts the skimming code and executes it in memory. The skimming code executes dynamically so it never present on the merchant’s server or saved to the customer’s computer.

Once the skimmer gets executed it captures the data from the checkout form, it keeps on scanning the fields for every 100 milliseconds. If it fetches the data then it sets a flag called ‘this.load’ indicating the skimmer successfully exfiltrated data.

The last process of the skimmer is cleaning up if the data is exfiltrated successfully it removes the entire skimming code from memory to avoid detection.

Visa asks merchants to regularly scan and test eCommerce sites for vulnerabilities or malware, ensure shopping carts, other services, and all software are upgraded or patched.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates

Also Read:

Lazarus APT Hackers Attack Japanese Organization Using Remote SMB Tool “SMBMAP” After Network Intrusion

PoetRAT – New Python RAT Attacking Government and Energy Sector Via Weaponized Word Documents

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

North Korean IT Workers Linked to 2,400 Astrill VPN IP Addresses

new data has emerged linking over 2,400 IP addresses associated with Astrill VPN to...

Laravel Framework Flaw Allows Attackers to Execute Malicious JavaScript

A significant vulnerability has been identified in the Laravel framework, specifically affecting versions between...

Critical Vulnerabilities in Moxa Switches Enable Unauthorized Access

A critical vulnerability identified as CVE-2024-12297 has been discovered in Moxa's PT series of...

Cobalt Strike Exploitation by Hackers Drops, Report Reveals

A collaborative initiative involving Microsoft’s Digital Crimes Unit (DCU), Fortra, and the Health Information...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

New PyPI Malware Targets Developers to Steal Ethereum Wallets

A recent discovery by the Socket Research Team has unveiled a malicious PyPI package...