Dozens of Credit Card Info Skimming Scripts Infect Thousands of Sites

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Malicious web code that Magecart groups use to steal payment card data from online stores is bustling business on underground forums. There are at least 38 unique families of such scripts, some more advanced than others, but each with multiple custom variants under their belt.

Coined by researchers at RiskIQ, the name Magecart refers to groups that scrape card data via malicious JavaScript code that loads on checkout pages. In late February, the company had discovered 12 distinct Magecart groups.
... ...
 

oldschool

Level 82
Verified
Top Poster
Well-known
Mar 29, 2018
7,157
Credit card usage is mostly unavoidable but may be limited to avoid some of the perils of web shopping. I use cash as often as possible locally. "Cash, still accepted at most locations!" Very old school. (y):)
 
  • +Reputation
  • Like
Reactions: shmu26 and stefanos

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
Anyone have a few wise words on how to make an online purchase and minimize risks? You can't just disable javascript because checkout won't work. You don't want to allow all scripts because then you are at risk. So how do you do it? How can you tell which scripts are legit? For instance, let's say I want to buy a gift card on Amazon. I see a whole bunch of scripts, and some of them are 3rd party:
Annotation 2019-04-04 082317.png


Or, let's say I want to donate to my favorite charity:
Annotation 2019-04-04 101756.png
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top