news.mlab.sh
Back to the feed
threat-intel

Credit card theft campaign abuses Stripe to host stolen payment info

High
Summary

A Magecart campaign is exploiting Stripe's infrastructure to steal credit card data from online stores. The attackers leverage Google Tag Manager to deliver the malicious code, bypassing standard security measures. This campaign utilizes Stripe's API to host stolen information, effectively turning the platform into a storage backend for compromised payment details.

The campaign, identified by ecommerce security company Sansec, targets online stores utilizing platforms like Magento/Adobe Commerce. Specifically, the malware focuses on checkout pages, attempting to capture sensitive information such as credit card numbers, expiration dates, CVV codes, customer names, billing addresses, and phone numbers. The attackers embed the malicious code within legitimate-looking Google Tag Manager (GTM) containers, which activate when a shopper reaches a checkout page, triggering Stripe's API for customer records. The stolen data is then obfuscated and stored locally, adding a layer of complexity to detection and recovery. A variant of the attack utilizes Google Firestore as an alternative data storage solution, further complicating efforts to identify and mitigate the threat.

Read the full article at BleepingComputer