#MageCart
PSA: If you have recently made a purchase from Canada Computers with a credit card, you will probably want to have that card cancelled.

"The malware is a Magecart-style script that listens for keystrokes on input fields, validates them, and steals them."

Please let your Canuck friends know.
January 22, 2026 at 9:33 PM
I brought Varys into this investigation and she might be the most amazing web injects hunter I have ever crossed paths with. Just amazing work. medium.com/@ping.from.d...
September 23, 2026 at 9:42 PM
Claude Code Security and Magecart: Getting the Threat Model Right
Claude Code Security and Magecart: Getting the Threat Model Right
thehackernews.com
March 18, 2026 at 12:53 PM
I've been cooking such detection capability for a few years now and felt it was time we released it to the world to aide with detection of e-skimmers.

So we did and my code is now up for all to use

github.com/Santandersec...
GitHub - Santandersecurityresearch/e-Skimming-Detection: Semgrep Rules for Detecting Magecart Skimmers and Obfuscated JavaScript
Semgrep Rules for Detecting Magecart Skimmers and Obfuscated JavaScript - Santandersecurityresearch/e-Skimming-Detection
github.com
January 24, 2025 at 1:09 PM
This campaign bears striking similarity to 2021 GTM-based Magecart operation that hit 316 sites and compromised 88,000 cards.

Same core TTPs being recycled.
February 11, 2025 at 5:45 PM
Currently listening to @scotthelme.bsky.social and @troyhunt.bsky.social talking about PCI DSS (Payment Card Industry Data Security Standard) 4.0.1 new requirements, Magecart attack (more like attacks, sadly) and stuff.
November 26, 2024 at 8:10 PM
Magecart Attackers Abuse Google Ad Tool to Steal Data
Magecart Attackers Abuse Google Ad Tool to Steal Data
www.darkreading.com
February 10, 2025 at 5:17 PM
#Magecart #Skimmer just triggered my #Canarytoken.
2 different shops, one was a 1 dollar transaction attempt, likely to test if the card works. The second was a transaction of 1604 canadian dollars in an attempt to buy something from
Viwoods Aipaper.
Actor = Canadian?
@thinkstcanary.canary.tools
January 7, 2025 at 1:35 PM
On January 13th 2026, SilentPush released an article about a #MageCart campaign.
Curious, I submitted a @ThinkstCanary CreditCard Token. 4 days ago, it triggered for the first time. Dwelltime: 4 months!
Carddata Testing done via @amazon prime and a US based charity.
#magecart #ccfraud #webskimming
May 18, 2026 at 4:12 PM
We're tracking an active Magecart campaign targeting ecommerce sites.

The malware hides from admins, adapts to the platform, and changes how it steals payment data!

Write-up: scotthelme.co.uk/fighting-an-...
Fighting an active Magecart Campaign
We’ve been tracking an active Magecart campaign targeting ecommerce sites, with payloads customised per victim and evasion logic designed to stay hidden from site owners. We spotted it because we moni...
scotthelme.co.uk
April 13, 2026 at 10:57 AM
Online shoppers, beware: Magecart skimming attacks are targeting major payment networks like American Express, Diners Club, Discover, and Mastercard.

Stay informed and protect your data with our latest article.
Online shoppers at risk as Magecart skimming hits major payment networks
A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.
www.malwarebytes.com
January 15, 2026 at 8:06 PM
👉🏻 “Magento Credit Card Stealer Disguised in an Tag”

🔗 blog.sucuri.net/2025/02/mage...

Clever work…
Magento Credit Card Stealer Disguised in an <img> Tag
Get insights into how MageCart attackers mask credit card stealing scripts within innocent-looking image tags.
blog.sucuri.net
February 19, 2025 at 3:11 PM
Magecart hackers exploit over 100 domains to hijack eStore checkouts, stealing payment data across 12 countries. Banks and cardholders face significant financial impacts. #CyberSecurity #Magecart #eCommerce #DataBreach Link: thedailytechfeed.com/magecart-hac...
April 2, 2026 at 5:36 PM
A new campaign used AI agents to automate attacks on 100+ companies, stealing over 600,000 credit cards. The AI handled reconnaissance, exploitation, and data destruction for as little as $25 per target. #AI #Cybercrime #DataBreach #Magecart

🌐 cyber[.]netsecops[.]io
AI Agents Used to Steal 600,000+ Credit Cards in Automated Attacks
A Chinese-speaking hacker used commercially available AI agents to automate attacks, breaching over 100 companies and stealing more than 600,000 credit...
cyber.netsecops.io
September 25, 2026 at 8:31 PM
It makes use of @semgrep.bsky.social and shouldn't take much to whip up some Python/Go code to scan all your infrastructure on a daily basis, pull down the JavaScript and scan it for ugliness.

Time to make life harder for Magecart and other groups
January 24, 2025 at 1:09 PM
Then we head to the checkout aisle to ask why JavaScript on online payment pages went feral, and how new PCI DSS rules are finally muzzling Magecart-style skimmers.

All this, and our recommendations for a couple of great apps for Mac users.
How to hack a prison, and the hidden threat of online checkouts
open.spotify.com
October 23, 2025 at 7:11 AM
Magecart attacks exploit third-party resources to steal payment data, bypassing static code analysis. Learn how integrating runtime monitoring can bolster your defense. #CyberSecurity #Magecart #WebSecurity Link: thedailytechfeed.com/static-code-...
March 19, 2026 at 6:47 PM
Magecart can hide in third-party favicon EXIF data, bypassing repo scans. With Claude Code Security, static analysis stops here—runtime execution on the client side begins.
Claude Code Security and Magecart: Getting the Threat Model Right
Magecart hides payload in favicon EXIF via third-party scripts, bypassing static analysis and stealing checkout data at runtime.
thehackernews.com
March 21, 2026 at 7:29 AM
The European Space Agency got hacked, and now we own the domain used!

Here's my blog post with details: scotthelme.co.uk/the-european...

And here's the domain if you want to try it, but I can't link it as it's flagged as malicious: esaspaceshop[.]pics
The European Space Agency got hacked, and now we own the domain used!
It's not often that two of my interests align so well, but we're talking about space rockets and cyber security! Whilst Magecart and Magecart-style attacks might not be the most common attack vector a...
scotthelme.co.uk
February 2, 2026 at 3:13 PM
Claude Code Securityが、サードパーティ製ファビコンのEXIFデータに隠されたMagecartペイロードを検知できない場合がある。
Claude Code Security and Magecart: Getting the Threat Model Right
Magecart hides payload in favicon EXIF via third-party scripts, bypassing static analysis and stealing checkout data at runtime.
thehackernews.com
March 18, 2026 at 12:55 PM
ESA's online store was Magecart-attacked on Dec 23, 2024. Hackers used a fake Stripe page to steal customer data via domain spoofing. The ESA says the third-party infrastructure minimized impact. The attack was likely financially motivated.#ESAMagecartAttack
December 26, 2024 at 1:10 PM
Magecart hits continue, as attackers turn their e-skimming sights to WooCommerce platforms w/ Stripe enabled. Separately, cloud-based ConnectPOS point-of-sale software left code repositories publicly exposed, placing customers at supply-chain attack risk www.databreachtoday.com/magecart-hit...
Magecart Hits Continue: Stripe Spoofing, Supply Chain Risks
Magecart-style digital skimming attacks targeting payment card data continue, with researchers detailing an active campaign targeting the popular WooCommerce
www.databreachtoday.com
January 14, 2026 at 2:28 PM
🚨 3.5k+ sites hijacked for crypto mining

A stealthy JS campaign is back: 3.5k+ websites secretly mine #crypto via obfuscated scripts, WebSockets, & Web Workers. Linked to #Magecart infra, blending #skimming & mining in a persistent digital drain.

#ransomNews #CyberSecurity #Infosec
July 21, 2025 at 1:37 PM
Magecart attacks hide malicious code in dynamically loaded third-party assets and EXIF metadata, bypassing repository-based static analysis tools like Claude Code Security because the code never enters the source repository.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
March 18, 2026 at 12:54 PM