Tuesday, August 25, 2026

New Magecart Campaign Steals Credit Card Details During Online Checkouts

Cybersecurity researchers at Silent Push Preemptive Cyber Defense have uncovered an extensive and sophisticated web-skimming campaign that has been actively stealing credit card data from e-commerce websites since at least January 2022.

The ongoing operation, operating under the umbrella term “Magecart,” targets multiple major payment networks including American Express, Diners Club, Discover, Mastercard, JCB Co., Ltd., and UnionPay, putting online shoppers and e-commerce platforms at significant risk.

The campaign represents a highly organized and technically advanced threat to online commerce.

The threat actors behind this campaign demonstrate advanced knowledge of WordPress internals and e-commerce platforms, specifically targeting websites using WooCommerce with Stripe payment integration.

Silent Push analysts discovered the operation while investigating indicators found on their Bulletproof Host Indicators Of Future Attack (IOFA) feeds, which led to the identification of a vast network of domains supporting the long-running credit card skimming infrastructure.

The attack methodology reveals sophisticated technical execution. Threat actors inject highly obfuscated JavaScript code into legitimate e-commerce checkout pages that runs client-side in victims’ browsers, making detection extremely difficult for both website owners and customers.

The malicious code monitors the Document Object Model (DOM) for changes and activates specifically when customers reach checkout pages to enter payment information.

Credential Theft Techniques

One of the most concerning aspects of this campaign is its advanced evasion capabilities. The skimmer code includes functionality to detect WordPress administrator sessions by checking for the “wpadminbar” element, completely removing itself from the page when site administrators are logged in.

This evasion technique significantly increases the malware’s survival rate and makes detection by website owners considerably more challenging.

The “i” function first executes yet another check for the existence of the “wc-stripe-form.” If it does not exist but the “wc-stripe-upe-form” done.

Screenshot of the web skimmer creating a malicious iframe.
Screenshot of the web skimmer creating a malicious iframe.

The attack creates a convincing fake payment form by hiding the legitimate Stripe payment interface and replacing it with a malicious iframe that mimics authentic payment fields.

The fraudulent form includes sophisticated validation features such as automatic card brand detection, proper formatting of card numbers based on provider standards (American Express uses 4-6-4 formatting while most cards use 4-4-4-4), expiration date validation, and error highlighting in red for invalid entries.

These features make the fake form virtually indistinguishable from legitimate payment interfaces to unsuspecting customers.

Once victims complete the fake payment form and click the “Place Order” button, the skimmer captures comprehensive personal and financial data including names, addresses, phone numbers, email addresses, credit card numbers, expiration dates, and CVV codes.

The stolen data is then JSON-formatted, XOR-encrypted with the hardcoded key “777,” Base64-encoded, and transmitted via HTTP POST request to the exfiltration server.

Silent Push identified multiple exfiltration domains, including lasorie[.]com and cdn-cookie[.]com, with the latter hosted on ASN 209847, recently acquired by European-sanctioned entity PQ.Hosting/Stark Industries.

Total view of cdn-cookie[.]com.
Total view of cdn-cookie[.]com.

After successful data theft, the skimmer removes the fake form, restores the legitimate Stripe interface, and simulates a click on the actual checkout button.

This causes an error message to appear since no data was entered in the real form, leading victims to believe they simply made a mistake.

Most shoppers then re-enter their information into the now-visible legitimate form and complete their purchase, remaining completely unaware that their payment credentials were already compromised.

Implications

The campaign’s longevity and technical sophistication underscore the persistent threat that web-skimming operations pose to e-commerce security.

In the case of colunexshop[.]com, the initiation of the request is done by a small piece of code in the file:

Screenshot of the code for colunexshop[.]com.
Screenshot of the code for colunexshop[.]com.

Enterprise organizations using the targeted payment providers face heightened risk, and the attack’s global reach across multiple payment networks suggests widespread potential impact.

Silent Push has scheduled a threat intelligence webinar titled “Magecart Unmasked” for February 3, 2026, to discuss identification of hidden Magecart activity and protective measures organizations can implement.

Security experts recommend that e-commerce platforms implement robust Content Security Policies (CSP), conduct regular security audits of third-party scripts, monitor for unauthorized changes to checkout pages, and deploy web application firewalls configured to detect suspicious JavaScript injections.

For consumers, vigilance regarding unexpected payment errors during checkout and monitoring credit card statements for unauthorized transactions remain critical defensive practices.

Due to operational security concerns, Silent Push has limited public disclosure of specific technical fingerprints and tracking methodologies, making complete details available only to enterprise clients and law enforcement agencies.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands

ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large...

Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records

A multi-agent AI framework, utilizing Hermes and OpenClaw agents,...

Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A cluster of fraudulent websites impersonating Microsoft is using...

Multiple Zscaler Client Connector Flaws Enable Remote Code Execution

Zscaler has addressed several vulnerabilities in its Client Connector...

91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain

Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs)...

PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2

PavinLoader, a multi-stage .NET malware loader, operating across ClickFix,...

Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls

Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP)...

Related Articles

Recent News