Feedify, a customer engagement service, was hacked after it was discovered that one of the service's scripts contained MageCart code. MageCart is a malicious script that can steal credit card information when a user fills out forms on a site.

To use Feedify's service, you need to add a JavaScript script to the website you manage. If the Feedify script contains MageCart, then the malicious code is "loaded" by all visitors to the page.
A researcher named Placebo made a relevant post on Twitter informing about the use of MageCart, and the company soon proceeded to remove the malicious code.
Specifically, Placebo created an account on Feedify so that he could see exactly what code each user had to embed on his website. He then checked a suspicious JavaScript script called feedbackembad-min-1.0.js. With a quick glance, he noticed that all forms filled out by the user were being recorded and sent to info-stat.ws/js/slider.js.
To confirm its finding, Placebo contacted other researchers from RiskIQ, who confirmed that the malicious script existed.
At the time of writing, Feedify has removed the malicious code from feedify.net/getjs/feedbackembad-min-1.0.js, but not from cdn.feedify.net/getjs/feedbackembad-min-1.0.js.
However, Feedify is not the first case of MageCart. One of the most recent cases is British Airways , which leaked credit card details of approximately 380,000 of its customers. RiskIQ once again helped with the investigation .
