Malicious actors have been observed using swap files on compromised Magento websites to hide a persistent Credit Card Skimmer and collect information .
See also: New Caesar Cipher Skimmer Targets WordPress, Magento, and OpenCart Sites

The sneaky technique, observed by Sucuri on the checkout page of a Magento e-commerce site, allowed the malware to survive multiple cleanup attempts.
The Credit Card skimmer is designed to collect all data on Magento websites and funnel the data to an attacker-controlled domain named “amazon-analytic[.]com”, which was registered in February 2024.
“Consider the use of branding; this tactic of spoofing popular products and services on domain names is often used by malicious actors in an attempt to avoid detection,” said security researcher Matt Morrow.
This is just one of many defense evasion methods used by the threat actor, which also includes using swap files (“bootstrap.php-swapme”) to load the malicious code, while keeping the original file (“bootstrap.php”) intact and malware-free.
While it is currently unclear how initial access in this case, it is suspected that it involved the use of SSH or some other terminal session.
See also: CosmicSting flaw affects Adobe Commerce and Magento

The revelation comes as compromised administrator accounts on WordPress are being used to install a malicious plugin that masquerades as the legitimate Wordfence, but comes with capabilities to create fake administrators and disable Wordfence, giving the false impression that everything is working as expected.
“For the malicious add-on to have been placed on the website in the first place, the website would have had to have already been compromised – but this malware could certainly serve as a vector for a re-infection,” said security researcher Ben Martin.
It is recommended that website owners limit the use of common protocols such as FTP, sFTP , and SSH to trusted IP addresses, as well as ensure that content management systems and plugins are up to date.
Users are also advised to enable two-factor authentication (2FA), use a firewall to block bots, and enforce additional security implementations in wp-config.php, such as DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS.
See also: Hackers exploit Magento vulnerability and insert backdoor into sites
Credit Card Skimmeris software used by criminals to illegally collect credit or debit card data on Magento websites. These skimmers can blend seamlessly with the original hardware, making them difficult for users to detect. When an unsuspecting person swipes their card, the skimmer captures the card information, which can then be used for unauthorized transactions or identity theft. As awareness grows, many manufacturers and service providers are implementing security features to combat skimming, including chip technology and improved tracking systems. It is important for consumers to remain vigilant and regularly monitor their financial transactions for suspicious activity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
