HomeSecurityWebRTC Skimmer bypasses CSP and steals payment data

WebRTC Skimmer bypasses CSP and steals payment data

Cybersecurity researchers have uncovered a highly sophisticated method of intercepting payment datathat is significantly different from well-known skimming. Instead of relying on traditional communication channels, such as HTTP requests or image beacons, the new skimmer leverages WebRTC Data Channels, creating an inconspicuous path for data transfer and bypassing security mechanisms.

WebRTC Skimmer

How the attack works and why it is more dangerous

According to Sansec 's analysis , the skimmer operates as a self-executing script that creates a direct WebRTC peer-to-peer connection with a remote server . Through this connection, the malware dynamically downloads a JavaScript payload , which is embedded in the payment page with the aim of stealing sensitive user data.

See also: New Caesar Cipher Skimmer Targets WordPress, Magento, and OpenCart Sites

The use of WebRTC is a critical differentiator, as the technology was designed for real-time communication rather than traditional HTTP data transfer. This means that the activity is not easily captured by monitoring tools network that rely on HTTP traffic inspection, making detection extremely difficult.

The PolyShell vulnerability is at the center of attacks

The attack is based on exploiting the PolyShell vulnerability, which affects Magento Open Source and Adobe Commerce. Through this weakness, attackers gain the ability to upload arbitrary executable files via the REST API and execute malicious code without authorization.

The exploit activity has reached the scale of a massive campaign since March 19, 2026, with over 50 IP addresses participating in automated scans of vulnerable systems. Data shows that over 56% of stores exposed to the vulnerability have already been targeted, underscoring the severity of the situation.

WebRTC Skimmer bypasses CSP and steals payment data

CSP bypass and detection difficulty

One of the most concerning aspects of the new technique is its ability to bypass Content Security Policy (CSP). Even in environments with strict measures that block unauthorized HTTP connections, WebRTC remains operational, opening a “window” for malicious activity.

See also: Malware targets WooCommerce sites and steals credit card data

Furthermore, communication via WebRTC DataChannels is carried out using encrypted UDP (DTLS), which makes monitoring even more difficult. Traditional security tools that focus on HTTP traffic are essentially “blinded” to this form of data extraction.

Delays in patches and increasing risk

Although a patch for PolyShell has already been released in version 2.4.9-beta1, it has not yet been integrated into stable production releases. This creates a dangerous security gap, as businesses relying on the affected platforms remain exposed.

The delay in the release of fully stable patches is a perennial problem in the e‑commerce space, where the need for uptime often delays the deployment of critical security updates.

WebRTC Skimmer bypasses CSP and steals payment data

Protective measures and best practices

Experts recommend immediate measures to mitigate the risk. These include blocking access to sensitive directories such as “pub/media/custom_options/,” as well as systematically scanning systems for web shells, backdoors, and suspicious scripts.

See also: New Skimmer malware steals credit card data

At the same time, enhancing network monitoring with tools that can analyze UDP and WebRTC traffic is now essential. Businesses are urged to reconsider their security strategies, taking into account that attackers are turning to increasingly sophisticated techniques.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This development demonstrates that the cyberattack landscape is constantly changing, with attackers exploiting technologies originally designed for legitimate use. For e-commerce businesses, vigilance and rapid adaptation are no longer an option, but a necessity.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS