Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment details



  • Attackers abuse Stripe API via Google Tag Manager
  • Malware skims checkout data from compromised Magento sites
  • Stolen card details exfiltrated through api.stripe.com

Cybercriminals have turned Stripe into a malware hosting platform, in a new attack that steals people’s payment information from online shoppers. This is according to cybersecurity researchers Sansec, who discovered the campaign earlier this week.

Sansec says that the attackers managed to compromise certain Magento/Adobe Commerce store websites, and add a malicious Google Tag Manager (GTM) container.

https://cdn.mos.cms.futurecdn.net/MduN7MRK2ES7Ue24joFtbT-2059-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img