Credit card swipers are injected into random plugins of e-commerce WordPress sites, hiding from detection while stealing customers' payment details.

See also: Hackers send SMS pretending to be from the Iranian government
With the holiday shopping season in full swing, card-stealing threat actors are increasing their efforts to infect online stores with hidden skimmers, so administrators should remain vigilant.
The latest trend is injecting card skimmers into WordPress plugin files, avoiding the closely monitored core “wp-admin” and “wp-includes” directories, where most directories are short-lived.
Hiding in plain sight
According to a new report from Sucuri, hackers who commit credit card theft first break into WordPress websites and insert a backdoor into the site for persistence.
These backdoors allow hackers to maintain access to the website, even if the administrator installs the latest security updates for WordPress and installed plugins.
When attackers use the backdoor in the future, it will scan for a list of administrator users and use the authorization cookie and login credentials of the current user to access the website.

Threat actors then add their malicious code to random plugins, and according to Sucuri, many of the scripts are not obfuscated.

However, upon examining the code, analysts noticed that an image optimization plugin contained references to WooCommerce and included undefined variables. This plugin has no vulnerabilities and is believed to have been randomly selected by the threat actors.
Using PHP's 'get_defined_vars()', Sucuri was able to discover that one of these undefined variables refers to a domain hosted on an Alibaba server in Germany.
This domain did not link to the compromised website they were looking for, which operates in North America.
See also: Ukraine arrests hackers from the "Phoenix" group
The same site had a second injection of the “404-page plugin,” which kept the actual credit card skimmer using the same approach of hidden variables in unobfuscated code.
In this case, the variables '$thelist' and '$message' were used to support the credit card skimming malware, with the former referring to the download URL and the latter using 'file_get_contents()' to capture the payment details.

How to protect yourself from card skimmers
Administrators can follow various protective measures to keep their sites skimmer-free or minimize infection times as much as possible.
First, the wp-admin area should be restricted to specific IP addresses only. Then, even if a backdoor, hackers could not access the site even if they managed to steal the administrator cookies.
See also: Hackers exploited flaw in popular e-commerce software
Secondly, file integrity monitoring via active server-side scanners should be implemented on the website, ensuring that no code changes go unnoticed for a long time. Finally, make it a habit to read log files and look at the details in detail.
Information source: bleepingcomputer.com
