getInjector is a client-side web skimming/keylogging malware family identified by Sansec in multiple campaigns. It uses a two-stage JavaScript loader designed to evade detection: the first stage checks whether the current page URL contains "checkout" and, if so, loads a second-stage script from attacker-controlled infrastructure such as https://js-csp.com/getInjector/. The loader uses character-code obfuscation to hide strings including the checkout trigger and external URL. The second-stage payload harvests form data from input, select, and textarea elements, including login credentials, payment card numbers, and personal information, and exfiltrates the stolen data via an image beacon to endpoints such as https://js-csp.com/fetchData/ with base64-encoded data and page-origin parameters. Sansec linked the malware to at least five getInjector campaigns in the prior 12 months, including a previous incident targeting the Green Bay Packers and a 2026 intrusion affecting the employee merchandise store of a top-three U.S. bank serving more than 200,000 employees. Reported related infrastructure includes js-csp.com, artrabol.com, js-stats.com, js-tag.com, and jslibrary.net, commonly using /getInjector/ and /fetchData/ paths. Sansec noted poor industry detection at the time referenced, with VirusTotal showing only 1 of 97 vendors flagging js-csp.com/getInjector/.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Security researchers at Sansec have discovered an active keylogger planted on the employee merchandise store of a “top 3 US bank,” potentially exposing the credentials and personal data of over 200,000 employees. The malware ... was designed to intercept “everything typed into the site’s forms: login credentials, payment card numbers, personal information”.
Security researchers at Sansec have discovered an active keylogger planted on the employee merchandise store of a “top 3 US bank,” potentially exposing the credentials and personal data of over 200,000 employees. The malware ... was designed to intercept “everything typed into the site’s forms: login credentials, payment card numbers, personal information”.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A two-stage web-based malware campaign that conditionally loads a second-stage payload on checkout pages, harvests all form data entered by users, and exfiltrates the stolen data via an image beacon to evade detection.
A two-stage, client-side JavaScript injection that conditionally loads a second-stage payload on checkout pages, harvests form fields (credentials, payment card data, PII), and exfiltrates the stolen data via an image-beacon request to attacker-controlled /fetchData/ endpoints.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.