
Hackers are targeting WooCommerce sites with a special JavaScript-based card-skimmer malware, which allows stolen credit card detailswithout having to redirect payments to accounts controlled by the hackers.
WooCommerce is a free, open-source WordPress plugin used on more than 5 million sites and facilitates e-commerce.
This is not the first time WooCommerce e-shops have been involved in credit card theft attacks (also known as Magecart attacks ), as stated by Willem de Groot of Sanguine Security . In August 2018, hackers attempted to compromise WooCommerce sites using brute-forcing techniques to discover administrator passwords
“Of course, WooCommerce and other WordPress-based e-commerce sites have been targeted by hackers in the past, but they were usually limited to modifications to payment details,” explained Ben Martin of Sucuri.
"For example, hackers were forwarding payments to the attacker's PayPal email instead of the legitimate site owner's account. What we're seeing now is something quite new."

New card skimming approach
The attack was discovered by Martin after several users of WordPress and WooCommerce sites reported fraudulent credit card transactions.
A check of all core files of the affected online stores revealed files with malicious code added to the end of seemingly harmless JavaScript files.
“The JavaScript itself is a little difficult to understand, but one thing that is clear is that the skimmer stores both the credit card number and the CVV (card security code) in plain text in the form of cookies,” Martin said.
"As is common in PHP malware, multiple layers of coding are used in an attempt to evade detection and hide the underlying code.".
What makes this attack stand out is that the attackers behind it included the JavaScript card skimmer in the core files of the site instead of loading it from a third-party site under their control (this usually happens in attacks aimed at stealing credit card information).
The skimmer cleans its tracks
The stolen credit card details are stored in two files image stored in the wp-content/uploads directory.
However, as Martin discovered, the skimmer had the ability to cover its tracks, as the files had been emptied when the analysis of the compromised sites began.
While usually the entry point used by attackers to infect a WooCommerce or other e-commerce site is easy to spot, this time it wasn't so obvious.
"It could have been a compromised administrator account, an SFTP password, or some vulnerable software," Martin added.
“One thing I would recommend to anyone concerned about the security of their WooCommerce or WordPress site is to disable direct file editing by adding the following line to wp-config.php,” he said.
