A sophisticated web-skimming campaign has been discovered, leveraging a deprecated Stripe API to validate stolen credit card data before exfiltration.
This novel strategy ensures that only valid and usable card details are exfiltrated, making the operation highly efficient and harder to detect.
Detailed insights into the attack have revealed alarming trends and vulnerabilities affecting numerous online merchants globally.
The skimming campaign unfolds in multiple stages, each meticulously designed to evade detection and maximize the attack’s efficacy.
Jscrambler research identified 49 compromised merchants, though the number is expected to rise as the campaign evolves. Noteworthy findings include:
Interestingly, a variant of the attack targeted Square payment systems, demonstrating the campaign’s diversity in targeting major payment service providers (PSPs).
Attackers exploit Stripe’s API to pre-validate stolen card details directly in the browser. This approach offers several advantages:
To counter such advanced threats, merchants and PSPs are urged to implement robust security measures:
The evolving tactics of this campaign underscore the sophistication of modern web skimming operations.
By leveraging a legacy Stripe API, attackers not only streamline their operations but also enhance their stealth. As cyberattacks grow in complexity, merchants must remain vigilant and prioritize client-side security.
Jscrambler continues to monitor this campaign and advises all online merchants to proactively safeguard their websites. For those suspecting compromise, immediate professional security assessment is recommended to mitigate potential damage.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…
A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…
A surge in phishing text messages claiming unpaid tolls has been linked to a massive…
The State Bar of Texas has confirmed a data breach following the detection of unauthorized…