A new attack may have compromised thousands of websites. As it became known, hackers attacked two services designed for websites. These services are Alpaca Forms and Picreel. Their breach may have resulted in the infection of 4,600 websites with malicious code.
With the malicious code, hackers have the ability to obtain all the data entered into the forms. We don't know exactly how the hackers managed to breach the services, but it is suspected that they breached Cloud CMS' CDN and modified one of the service's scripts. Cloud CMS developed the open source Alpaca Forms service about 8 years ago.
The attacks were discovered by researcher Willem de Groot. According to reports, when Cloud CMS was notified of the breach, it disabled the CDN that served the malicious script.
A few words about compromised services
Alpaca Forms is an open source service that helps create HTML5 forms for mobile and web applications. The service offers many features and makes it easy for users to create forms, as it uses JSON Schema and Handlebars.
Cloud CMS CTO Michael Uzquiano said that only one JavaScript file from Alpaca Forms on the CDN service was compromised.
As we mentioned above, the malicious code records the information entered into the forms. Typically, this is passwords, financial data, payments and more. It then sends this information to a server located in Panama and controlled by the hackers.
The Picreel service tracks the movements of site (mouse movements in real time). In this way, site owners know the preferences of users and display targeted advertisements. It is assumed that the sites have a JavaScript code embedded, which allows the service to do its job. This code has been compromised by hackers and malicious software has been added.
The malicious code in the Picreel script has been found on 1,249 websites, while the code in Alpaca Forms has been found on 3,435 domains.
Cloud CMS, after disabling the CDN with the malicious script, launched an investigation. According to them, there is no problem with Cloud CMS, its customers, or its products.
However, it appears that the same hackers are behind both attacks.
