Multiple Japanese B2C e-commerce sites were compromised in a web skimming campaign that stole customers’ personal information, login credentials, and payment card data by injecting malicious JavaScript into checkout, login, and registration pages. Reporting from LAC linked the activity to techniques similar to Water Pamola, which Trend Micro and JPCERT/CC previously described as abusing malicious order submissions containing XSS payloads; when viewed in merchant administration panels, the payloads executed in administrators’ browsers, enabling credential theft, web shell deployment, and further compromise of the online store.
The campaign affected sites built on EC-CUBE as well as other platforms, indicating the attackers were targeting exploitable e-commerce implementations rather than a single product. The skimming code evolved over time, including increased obfuscation and infrastructure changes from googlevapis[.]com to jqueryapistatic[.]com, while some incidents used the victim’s own domain as an HTTPS exfiltration endpoint to reduce detection. Investigators said the attackers harvested cardholder names, card numbers, expiration dates, security codes, email addresses, and passwords, and recommended patching platforms and plugins, restricting administrator access, enabling MFA, deploying WAF protections, and reviewing logs for connections to known malicious domains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2022-04-07, LAC reported multiple domestic Japanese B2C e-commerce sites had been compromised and modified with malicious JavaScript on checkout, login, and registration pages. The scripts stole personal and payment card data and exfiltrated it over HTTPS, sometimes to attacker-controlled endpoints hosted on other compromised e-commerce domains.
LAC observed that the attackers newly registered jqueryapistatic[.]com on 2021-11-07 and soon began using it in attacks. LAC assessed that updated malicious scripts were migrated from the previously used googlevapis[.]com infrastructure to this new domain.
On 2021-07-12, JPCERT/CC published follow-up reporting on the e-commerce attacks, including attacker infrastructure indicators and hashes tied to the campaign. The report emphasized that the attacks were not specific to EC-CUBE and could also succeed through vulnerable plugins.
JPCERT/CC stated the attack campaign was still ongoing as of 2021-07-01 and had confirmed similar cases affecting websites developed with EC-CUBE products. It described attackers stealing administrator credentials, deploying web shells and Adminer, and planting JavaScript to capture customer login and payment data.
On 2021-04-28, Trend Micro published research describing Water Pamola's use of malicious shopping orders with embedded XSS to compromise online shops. It also noted that at least one attacked site later disclosed a breach involving possible theft of names and payment card data.
Trend Micro said it had tracked Water Pamola activity since 2019, in which attackers targeted e-commerce sites by submitting orders containing XSS payloads that executed in merchant administration panels. The campaign used follow-on payloads for actions including page grabbing, credential phishing, web shell deployment, and malware delivery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
lac.co.jp
Open sourceblogs.jpcert.or.jp
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.