2026 began with worrying signs for e-commerce security , as cybersecurity researchers recorded the resurgence of a sophisticated web-skimming campaign . This attack directly targets the checkout process , stealing sensitive payment details in real time. The campaign is attributed to the broader Magecart threat family , a collective name for cybercriminal groups that specialize in stealing card data via malicious JavaScript. Although Magecart has been around for years, the current version is considered one of the most technically advanced.
Infrastructure with a long history
According to researchers' analysis, this operation is not new. Its infrastructure appears to have been operating since at least early 2022, with gradual improvements to its code and obfuscation techniques. The fact that it has remained active for such a long time indicates a high level of organization and adaptability.
See also: PLUGGYAPE malware targets Ukraine via Signal & WhatsApp
The campaign targets large and small e-commerce websites that use popular payment platforms, including American Express, Mastercard, Discover, Diners Club, JCB and UnionPay. The potential reach of the attack reaches millions of consumers globally.

How web skimming works
The attack is based on injecting malicious JavaScript into legitimate websiteswithout immediately triggering security warnings. The code “hides” in the background and remains inactive until the user reaches the payment page. There, the skimmer is activated and data collection begins.
The attackers' infrastructure uses compromised domains and so-called bulletproof hosting providers, which make it difficult to detect and take down the malicious servers. This dramatically increases the lifespan of the campaign.
WordPress exploitation and technical complexity
Silent Push analysts point out that the attackers have deep knowledge of WordPress. They use lesser-known action hooks, such as wp_enqueue_scripts, to embed malicious scripts directly into the website loading process .
See also: deVixor: New Android banking malware
The technical complexity peaks on the payment page. The malware creates a MutationObserver, monitoring in real time any changes to the page's DOM. This ensures that it remains active even if dynamic elements are loaded.
The fake payment form that doesn't arouse suspicion
When the Stripe payment form is detected, the skimmer hides it and displays a nearly identical fake form. This captures card numbers, expiration dates, CVV, billing information, and personal data.
The scam is made even more convincing by a card-type recognition mechanism that displays the corresponding brand logos. To the average user, the experience looks completely legitimate.

Magecart: Data extraction and psychological manipulation
After the order is submitted, all data is collected, encrypted with XOR (key 777), encoded in Base64, and sent via HTTP POST to the attackers' servers.
Immediately afterwards, a supposed payment error appears . Victims believe they made a mistake and repeat the process, this time using the legitimate form. Thus, the purchase is completed normally, without the user suspecting that their data has already been stolen.
See also: VoidLink: New malware framework targets Linux systems
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Hiding from administrators and predictions for the future
The malware also has evasion mechanisms, detecting if the visitor is a WordPress administrator. In this case, it is deactivated, reducing the chances of detection.
Experts warn that the threat will continue to evolve throughout 2026. For online stores, regular updates, monitoring script changes, and strengthening frontend security are now the only way forward.
