Tuesday, September 8, 2026

Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers

Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily.

Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can blend in with legitimate site functionality, making detection significantly harder.

Once embedded into a compromised site, these containers allow hackers to inject custom JavaScript and HTML, enabling them to harvest sensitive payment data during checkout.

Recent investigations uncovered a spike in malicious Google Tag Manager containers actively used in web skimming campaigns.

One widely detected container, GTM-WJ6S9J6, appeared on at least 178 infected sites in 2023 and was ultimately removed by Google following abuse reports. However, before its takedown, it injected skimmer payloads from domains like gtm-statistic [.]com.

Security researchers in Sucuri warn that attackers only need a basic Google account to create a GTM container and begin distributing malicious code.

Attackers also registered lookalike domains such as gooqle-analytics[.]com and webstatlstics[.]com to impersonate legitimate analytics services and evade suspicion.


Spotting common GTM credit card skimmers (Source : Sucuri).
Spotting common GTM credit card skimmers (Source : Sucuri).

In some cases, multiple GTM scripts were chained together to deploy skimmers, complicating detection and analysis.

Magecart Hackers Exploit Google Tag Manager

A newer campaign involving container GTM-TVKQ79ZS revealed an updated version of the long-running ATMZOW skimmer.

New ATMZOW skimmer in GTM-TVKQ79ZS (Source : Sucuri).
New ATMZOW skimmer in GTM-TVKQ79ZS (Source : Sucuri).

This malware family has been active since at least 2015 and was previously linked to large-scale Magento compromises during the early Magecart era.

Despite years of exposure, the group behind ATMZOW continues to refine its techniques. The latest variant uses heavily obfuscated JavaScript that depends on the exact script length, making it fragile to analyze but highly resistant to traditional decoding methods.

For example, earlier variants used simple Base64 encoding to hide trigger conditions like targeting checkout pages.

In contrast, the newer code layers multiple decoding routines, requiring precise reconstruction before analysts can extract meaningful indicators.

One of the most notable changes is the use of 40 newly registered domains designed to appear benign. These domains follow a pattern combining art-related terms with analytics-style keywords, such as cdn.sketchanalyticsvault[.]com and cdn.visualartinsights[.]com.

40 new “artistic” domains (Source : Sucuri).
40 new “artistic” domains (Source : Sucuri).

Instead of loading all domains at once, the malware randomly selects two domains per infected browser session and stores them locally. This tactic limits visibility during traffic analysis, slowing down efforts to identify and block the full infrastructure.

Additionally, the domains were initially hidden behind Cloudflare protection to mask their origin.

Once uncovered, researchers traced them to Hostinger infrastructure, with IPs including 31.220.21[.]211 and 62.72.7[.]89. These same IPs were linked to earlier skimming campaigns, indicating infrastructure reuse.

Even after Google removed malicious containers like GTM-TVKQ79ZS, attackers quickly adapted by deploying new containers such as GTM-NTV2JTB4 and GTM-MX7L8F2M.

This rapid recycling highlights the persistence of Magecart groups and their ability to reinfect vulnerable sites.

In some cases, GTM-based skimmers were found alongside other threats, including WebSocket-based skimmers, suggesting attackers are layering multiple techniques to maximize data theft.

While many modern skimming campaigns have shifted toward WooCommerce platforms, ATMZOW continues to heavily target Magento-based ecommerce environments. This indicates that older, often unpatched Magento installations remain a lucrative target.

Security experts emphasize that GTM scripts should not be blindly trusted, even though they originate from a reputable domain. Any unauthorized or unfamiliar GTM container embedded in a website may indicate a compromise.

A practical example: if a checkout page suddenly loads additional scripts from unknown domains or triggers unexpected network requests, it could signal an active skimmer. Regular audits of GTM configurations and strict access controls are critical to preventing such attacks.

As Magecart groups continue to evolve, the abuse of trusted services like Google Tag Manager underscores a broader trend attackers are increasingly hiding in plain sight, leveraging legitimate tools to carry out large-scale payment data theft.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed...

Known npm Worm Returns After 111 Days and Security Scanning Still Let It Through

A known Shai-Hulud npm worm payload has resurfaced after...

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Related Articles

Recent News