Visa has issued a warning about a new e-commerce JavaScript skimmer known as Baka, which “leaves” itself from memory after extracting stolen data.
The credit card theft script was discovered by Visa's Payment Fraud Disruption (PFD) researchers in February 2020, while examining a command and control (C2) server that previously hosted an "ImageID web skimming kit."

Last year, Visa discovered another JavaScript web skimmer known as Pipka, which quickly spread to online stores after being initially detected on North American e-commerce sites in September 2019.
Avoiding detection and analysis
In addition to the normal basic scanning capabilities such as data exfiltration using image requests, Baka has an advanced design that indicates it is the project of a skilled malware developer.
“The skimmer is loaded dynamically to evade static malware scanners and uses unique encryption for each victim to hide the malicious code,” Visa’s alert states.
“PFD estimates that this skimmer variant evades detection and analysis by removing itself from memory when it detects the dynamic analysis capability with Developer Tools or when data has been successfully extracted.”
Baka was detected by Visa on multiple online stores across multiple countries.
Visa recommends that member financial institutions, e-commerce merchants, service providers and third-party vendors refer to its “What To Do If Compromised” (WTDIC) document for guidance if their payment systems are compromised.
