The Magecart hacking group has made another appearance, targeting the NutriBullet site this time
According to security firm RiskIQ, malicious actors managed to gain access to the blender maker's website multiple times over the past two months. They were able to insert credit card-stealing malware into the website and steal card numbers and other personal data, such as names, billing addresses, expiration dates, and card verification values, belonging to unsuspecting NutriBullet customers.
The data was extracted and sent to a server operated by the attackers. The stolen credit card data was then sold to buyers on the dark web.
NutriBullet responded to each attack by removing the malicious code. However, according to RiskIQ, the group still had access to the company's infrastructure and continued to attack the website, with the latest attack taking place last week.
RiskIQ's head of risk research, Yonathan Klijnsma, warned users not to use the site.
NutriBullet chief information officer Peter Huh confirmed the attacks and said the company has "initiated investigations" into the incident and claimed it will "work closely with external cybersecurity experts to prevent further intrusions," but did not provide any further information.
Hackers associated with Magecart's tactics have carried out other attacks in recent years on companies such as Ticketmaster, British Airways, the American Cancer Society and Newegg.
With the help of AbuseCH and Shadowserver, RiskIQ has begun efforts to take down the malicious domain used by the hackers to send the stolen credit card numbers. Of course, the group that has access to NutriBullet's infrastructure can continue to create new malicious domains and re-infect the site with malware to steal credit cards.

