HomeSecurityNew Magecart attack steals credit card details

New Magecart attack steals credit card details

2026 began with worrying signs for e-commerce security , as cybersecurity researchers recorded the resurgence of a sophisticated web-skimming campaign . This attack directly targets the checkout process , stealing sensitive payment details in real time. The campaign is attributed to the broader Magecart threat family , a collective name for cybercriminal groups that specialize in stealing card data via malicious JavaScript. Although Magecart has been around for years, the current version is considered one of the most technically advanced.

Infrastructure with a long history

According to researchers' analysis, this operation is not new. Its infrastructure appears to have been operating since at least early 2022, with gradual improvements to its code and obfuscation techniques. The fact that it has remained active for such a long time indicates a high level of organization and adaptability.

See also: PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

The campaign targets large and small e-commerce websites that use popular payment platforms, including American Express, Mastercard, Discover, Diners Club, JCB and UnionPay. The potential reach of the attack reaches millions of consumers globally.

Magecart

How web skimming works

The attack is based on injecting malicious JavaScript into legitimate websiteswithout immediately triggering security warnings. The code “hides” in the background and remains inactive until the user reaches the payment page. There, the skimmer is activated and data collection begins.

The attackers' infrastructure uses compromised domains and so-called bulletproof hosting providers, which make it difficult to detect and take down the malicious servers. This dramatically increases the lifespan of the campaign.

WordPress exploitation and technical complexity

Silent Push analysts point out that the attackers have deep knowledge of WordPress. They use lesser-known action hooks, such as wp_enqueue_scripts, to embed malicious scripts directly into the website loading process .

See also: deVixor: New Android banking malware

The technical complexity peaks on the payment page. The malware creates a MutationObserver, monitoring in real time any changes to the page's DOM. This ensures that it remains active even if dynamic elements are loaded.

The fake payment form that doesn't arouse suspicion

When the Stripe payment form is detected, the skimmer hides it and displays a nearly identical fake form. This captures card numbers, expiration dates, CVV, billing information, and personal data.

The scam is made even more convincing by a card-type recognition mechanism that displays the corresponding brand logos. To the average user, the experience looks completely legitimate.

New Magecart attack steals credit card details

Magecart: Data extraction and psychological manipulation

After the order is submitted, all data is collected, encrypted with XOR (key 777), encoded in Base64, and sent via HTTP POST to the attackers' servers.

Immediately afterwards, a supposed payment error appears . Victims believe they made a mistake and repeat the process, this time using the legitimate form. Thus, the purchase is completed normally, without the user suspecting that their data has already been stolen.

See also: VoidLink: New malware framework targets Linux systems

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New Magecart attack steals credit card details

Hiding from administrators and predictions for the future

The malware also has evasion mechanisms, detecting if the visitor is a WordPress administrator. In this case, it is deactivated, reducing the chances of detection.

Experts warn that the threat will continue to evolve throughout 2026. For online stores, regular updates, monitoring script changes, and strengthening frontend security are now the only way forward.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS