Cybersecurity experts have revealed the existence of a credit card hacker – skimmer, embedded in a fake Meta Pixel, aiming to bypass detection.

Sucuri of custom code. These include WordPress plugins like Simple Custom CSS and JS, as well as the “Miscellaneous Scripts” section in the Magento admin panel.
Read more: Russia: Accuses hackers of stealing credit cards
The web security firm's analysis revealed a fake Meta Pixel tracking script that contained elements similar to the official one. However, a closer look reveals one significant difference: the insertion of JavaScript code that replaces references to the address “connect.facebook[.]net” with “b-connected[.]com.”.
While the first domain corresponds to a genuine function , the domain used as a replacement serves the purpose of loading a malicious script (“fbevents.js”). This script detects whether a victim is on a checkout page and, if so, triggers a deceptive overlay with the aim of stealing their credit card details.
It is important to note that “b-connected[.]com” is an official e-commerce website that has been compromised in the past to allow hackers to insert malicious code. In addition, data submitted through the fake platform is passed to another compromised website, “www.donjuguetes[.]es”.
To avoid risks, it is important to keep your websites up to date, regularly inspect administrator accounts to confirm their validity, and regularly renew passwords.
Strengthening security is critical, as hackers often exploit weak passwords and vulnerabilities to break into targeted websites. Their goal is to appoint fake administrators, who may then perform further harmful actions, such as installing malicious backdoors.
See also: Crypto drainers exist on thousands of WordPress sites
“Credit card hackers typically search for specific keywords like 'checkout' or 'onepage,' which means that hacker attacks may not be noticed until the checkout page has fully loaded,” said Morrow.
Since checkout pages are configured using cookies and other elements, these scripts escape detection by scanners. The only way to deal with malware is to check the source code of the page or monitor network traffic. These scripts execute discreetly, remaining undetected in the browsing history.
Sucuri also reveals that websites built with WordPress and Magento are being targeted by a new malware, Magento Shoplift. Variants of Magento Shoplift have been detected spreading since September 2023, increasing the need for security.
The attack process begins by embedding an unspecified piece of JavaScript into a legitimate JavaScript file. This initial step is responsible for initiating the loading of a second script from the jqueurystatics[.]com address, using a secure WebSocket (WSS) connection. This second script is intended to facilitate credit card data extraction and information theft, while also impersonating a Google Analytics.
“WordPress has become a giant in the e-commerce space, thanks to the inclusion of Woocommerce and other extensions that easily transform a WordPress website into a fully functional online store,” said researcher Puja Srivastava.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: BidenCash: Offers 1.9 million stolen credit cards for free
The popularity of WordPress makes them a prime target for attacks, with hackers adapting the MageCart malware for e-commerce, now targeting a wider range of content management platforms (CMS).
Source: thehackernews
