Magecart is an umbrella term for financially motivated web-skimming malware and the criminal activity clusters that deploy it against e-commerce environments. Rather than a single codebase, it encompasses JavaScript-based payment skimmers that are injected into online stores, checkout components, or third-party web dependencies to steal payment and personal data in the browser during live transactions. Magecart activity has repeatedly targeted platforms such as Magento, Adobe Commerce, WooCommerce, WordPress-based stores, Salesforce Commerce Cloud deployments, and payment flows integrated with providers including Stripe, Redsys, PayPlug, and Authorize.net.
Magecart skimmers typically activate on checkout pages, monitor payment-related form elements, and capture card numbers, expiration dates, CVV values, billing details, names, email addresses, phone numbers, and sometimes account credentials. Many variants preserve the normal purchase flow so transactions still complete, which materially increases dwell time and reduces the chance of discovery. Common tradecraft includes injecting fake payment overlays or iframe-like forms that mimic legitimate processors, hooking checkout buttons and form events, dynamically mapping fields across different storefront layouts, validating card data in real time, and storing temporary state in browser storage to support deduplication or delayed transmission.
The malware family is notable for extensive defense evasion. Observed techniques include heavy JavaScript obfuscation, inline payloads hidden in HTML or SVG elements, disguising malicious code as analytics or tag-management snippets, use of trusted third-party infrastructure, anti-debugging logic, self-removal when administrator indicators are present, staged loaders that fetch store-specific skimmers, and exfiltration methods designed to resemble benign web traffic such as image beacons, analytics requests, WebSocket traffic, or backend API abuse. Some campaigns encrypt or encode stolen data before exfiltration and use resilient multi-stage infrastructure with fallback domains or bulletproof hosting.
Initial compromise vectors vary by campaign but commonly include vulnerable plugins, CMS flaws, supply-chain compromise of third-party scripts, misconfigured cloud storage, stolen or weak administrative credentials, and direct modification of store code or payment gateway components. Magecart operations have been linked to major breaches affecting large retailers and ticketing platforms, as well as broad campaigns compromising many smaller merchants simultaneously. The primary objective is theft and monetization of payment-card data, making Magecart one of the most persistent and consequential forms of client-side e-commerce malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Over 40,000 WooCommerce stores running the FunnelKit Funnel Builder plugin are exposed to a missing authorization flaw that allows unauthenticated attackers to inject JavaScript payment skimmers directly into checkout pages... References NVD Entry for CVE-2026-47100. | Sansec researchers have confirmed active exploitation, with threat actors deploying Magecart style skimmers that harvest credit card numbers, CVVs, and billing addresses from unsuspecting shoppers.
SessionReaper (CVE-2025-54236) is an unauthenticated, remote-code-execution flaw in Adobe Commerce / Magento that stems from nested deserialization in admin-facing functionality. Sansec’s forensics team said it blocked hundreds of real-world exploitation attempts of the SessionReaper bug as proof-of-concept code and a technical write-up circulated publicly.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The stolen data is concatenated into a single string, obfuscated using the XOR operation, and stored locally instead of immediately exfiltrated.
The code checks for user payment information and generates a random password to encrypt the payment details. The encrypted data is then dumped into an image file (.jpg) and made easily accessible. What is concerning about this attack is that the attackers took additional steps to encrypt the data with a public key in PEM format and a randomly generated string...
97 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
JavaScript-based web skimming malware used to compromise legitimate e-commerce sites and steal payment card data during real checkout sessions by injecting fake payment forms and exfiltrating captured details.
Web-based payment card skimmer used to steal checkout data from e-commerce sites. In this campaign it loads via Google Tag Manager, captures payment and customer information from Magento/Adobe Commerce checkout pages, obfuscates the data with XOR, stores it locally, and exfiltrates it via fake customer records in an attacker-controlled Stripe account; a variant uses Google Firestore for storage.
Web-based payment skimmer used to steal checkout data such as credit card numbers, CVVs, and billing addresses from WooCommerce checkout pages after malicious JavaScript injection.
A web-based payment skimming threat associated with injecting malicious scripts into ecommerce checkout pages to steal credit card numbers, CVVs, billing addresses, and other personal details.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.