Researchers linked a broader Magecart 12 web-skimming operation to the domain jquerycdn.su, identifying dozens of compromised online stores where malicious JavaScript was injected to steal shoppers’ payment data. The campaign was observed from at least late 2019 into early 2020, and investigators said many affected sites were still infected even after the skimmer infrastructure temporarily went offline. Any payment information entered on impacted checkout pages during the exposure window was assessed as potentially compromised.
Analysis of the malware showed the skimmer evolved through at least four iterations while keeping a consistent obfuscation style associated with earlier Magecart 12 activity. Earlier variants used a first-stage payload padded with garbage code, while newer versions expanded collection beyond standard payment forms to harvest all fields on a page, increasing the amount of customer data that could be captured. Researchers also tied the exfiltration infrastructure to other Magecart 12 campaigns, indicating a sustained and adaptable card-theft operation targeting e-commerce platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The author said they contacted all but three of the affected web shops by email or web form to warn them about the compromise.
The latest newly observed infection associated with the MageCart 12 jquerycdn.su campaign was identified on Kitchen And Couch, showing the operation was still adding victims in February 2020.
A follow-up investigation documented MageCart 12 payment-card skimming activity using the domain toplevelstatic.com, with infections observed across multiple e-commerce sites. The skimmer closely matched a previously seen opendoorcdn.com variant, and the earliest cited victim activity in this cluster began in late January 2020.
The earliest recorded infections tied to the MageCart 12 skimmer domain jquerycdn.su were observed on multiple online shops, marking the start of the documented web-skimming campaign.
As of 2020-02-25, several online shops were still serving the malicious code reference even though jquerycdn.su was offline, meaning payment data entered during infected periods should be treated as compromised.
By the time of writing, the skimmer-hosting domain jquerycdn.su had been down for several days, temporarily interrupting active card theft from some still-infected sites.
The jquerycdn.su campaign expanded across additional e-commerce sites over the following months, with the skimmer changing four times while maintaining the same general obfuscation approach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
riskiq.com
Open sourcemaxkersten.nl
Open sourcemaxkersten.nl
Open sourcemarcoramilli.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.