Magecart is an umbrella term for multiple financially motivated threat groups and the JavaScript-based web skimming malware they deploy against e-commerce environments. Magecart operations compromise online stores, payment portals, and related checkout infrastructure by injecting malicious client-side code into payment pages, third-party tags, locally hosted libraries, plugins, themes, or other web assets. The malware is designed to capture payment card data and associated customer information entered during checkout, including card numbers, expiration dates, CVVs, names, billing addresses, email addresses, phone numbers, and other form data, then exfiltrate that information to attacker-controlled infrastructure.
Magecart activity has affected a wide range of platforms and ecosystems, including Magento and Adobe Commerce, WooCommerce on WordPress, PrestaShop, Volusion, X-Cart, and government payment portals such as Click2Gov. Infection vectors include direct compromise of merchant websites, tampering with checkout plugins, abuse of public AJAX endpoints, modification of legitimate JavaScript libraries, insertion into Google Tag Manager containers, abuse of trusted third-party infrastructure such as Stripe and GitHub, and hybrid client-side/server-side skimming designs that stage stolen data through the victim site before forwarding it externally. Some campaigns also hide payloads in benign-looking assets such as PNG images or disguise skimmers as analytics, tag-management, or CDN resources.
Observed Magecart variants commonly activate only on checkout-related pages, hook payment form events, inject fake payment forms, overlay legitimate payment interfaces, or dynamically map and harvest input fields. Many samples use obfuscation, anti-debugging, integrity checks, local or session storage, deduplication logic, delayed exfiltration, or self-removal to evade detection and prolong dwell time. Exfiltration methods have included HTTP POST, image beacons, navigator.sendBeacon, WebSocket communications, same-site staging scripts, and abuse of external service backends.
Magecart is primarily associated with payment-card theft and broader e-skimming fraud rather than destructive or disruptive objectives. Stolen data is typically monetized through carding marketplaces and related fraud ecosystems. Public reporting has linked specific clusters and campaigns to multiple distinct Magecart groups, including activity associated with FIN6 in some cases, but the term itself remains a collective label rather than a single malware family or actor. The principal targets are online retailers and any organization operating web-based payment workflows, with victims ranging from small merchants to major retail brands and public-sector payment sites.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over 40,000 WooCommerce stores running the FunnelKit Funnel Builder plugin are exposed to a missing authorization flaw that allows unauthenticated attackers to inject JavaScript payment skimmers directly into checkout pages... References NVD Entry for CVE-2026-47100. | Sansec researchers have confirmed active exploitation, with threat actors deploying Magecart style skimmers that harvest credit card numbers, CVVs, and billing addresses from unsuspecting shoppers.
SessionReaper (CVE-2025-54236) is an unauthenticated, remote-code-execution flaw in Adobe Commerce / Magento that stems from nested deserialization in admin-facing functionality. Sansec’s forensics team said it blocked hundreds of real-world exploitation attempts of the SessionReaper bug as proof-of-concept code and a technical write-up circulated publicly.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered that the online credit card skimming attack known as Magecart or E-Skimming was actively operating on 3,126 online shops.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Those include a large number of cybercrime forums and stolen credit card shops, ransomware download sites, Magecart-related infrastructure, and a metric boatload of phishing Web sites...
The stolen data is concatenated into a single string, obfuscated using the XOR operation, and stored locally instead of immediately exfiltrated.
After the end of the last chunk (IEND), we can see JavaScript code. This code is ignored by image viewers, but you can access it if you work with the .png file as if it was a regular text file.
Like other JavaScript skimmers, Pipka is injected into websites to steal data that’s entered into online payment forms on e-commerce websites. When a visitor goes to that website, the skimmer will then scoop up personal details entered on the site – including payment-card information such as payment account number, expiration date, three-digit Card Verification Value (CVV) and the cardholder’s name and address.
Like other JavaScript skimmers, Pipka is injected into websites to steal data that’s entered into online payment forms on e-commerce websites. When a visitor goes to that website, the skimmer will then scoop up personal details entered on the site – including payment-card information such as payment account number, expiration date, three-digit Card Verification Value (CVV) and the cardholder’s name and address.
the script creates a new image tag with the src attribute pointing to the /get.php file on the same compromised site. The stolen data is passed along as GET parameters to that image.
The code checks for user payment information and generates a random password to encrypt the payment details. The encrypted data is then dumped into an image file (.jpg) and made easily accessible. What is concerning about this attack is that the attackers took additional steps to encrypt the data with a public key in PEM format and a randomly generated string...
176 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript-based web skimming malware used to compromise legitimate e-commerce sites and steal payment card data during real checkout sessions by injecting fake payment forms and exfiltrating captured details.
Web-based payment card skimmer used to steal checkout data from e-commerce sites. In this campaign it loads via Google Tag Manager, captures payment and customer information from Magento/Adobe Commerce checkout pages, obfuscates the data with XOR, stores it locally, and exfiltrates it via fake customer records in an attacker-controlled Stripe account; a variant uses Google Firestore for storage.
Web-based payment skimmer used to steal checkout data such as credit card numbers, CVVs, and billing addresses from WooCommerce checkout pages after malicious JavaScript injection.
A web-based payment skimming threat associated with injecting malicious scripts into ecommerce checkout pages to steal credit card numbers, CVVs, billing addresses, and other personal details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.