According to IBM researchers , the Magecart hacking group is attempting to inject malicious code into layer 7 (L7) routers .
These devices are very popular and are used by hotels, resorts, airports and other public locations. Specifically, the Magecart Group 5 (MG5) is trying to upload code to files loaded by these routers. The hackers' goal is to affect users shopping on American and Chinese sites.
Hackers are injecting code into a popular open-source JavaScript library, which websites commonly use. This code helps steal users' credit card information.
“Through this code, the MG5 group can infect and compromise the data of users who install infected apps on their mobile phones and then shop online,” IBM says.
The hackers are targeting a specific type of router, the layer 7 router, which can provide Wi-Fi connectivity to multiple users.
Administrators of these routers have the ability to control the content provided to all users connecting to them. This means that various issues regarding security . Content can be modified, redirected to other pages, and much more.

Hackers could use the router in a malicious way and affect users connected to it.
According to IBM researchers, the problem is that this router (as we said above) is used in public and crowded places and offers free Wi-Fi, which means that many users are connected.
Furthermore, the router administrators in these places do not take care to regularly update and fix any issues.
All of the above elements help hackers carry out effective attacks and steal card data.
In addition to data theft, users who connect to the infected router and are onlinemay be confronted with malicious advertisements.
