Silent Push reported a large-scale Magecart-style web-skimming operation active since early 2022 that uses an extensive domain network to support client-side JavaScript skimmers on compromised e-commerce checkout pages. The activity is assessed to impact online shoppers and organizations that are clients of major payment providers, with targeting noted against American Express, Diners Club, Discover, JCB, Mastercard, and UnionPay; the skimmers are designed to quietly exfiltrate payment-card and other form data during transactions rather than disrupt systems.
Technical reporting tied the infrastructure to domains hosting highly obfuscated skimmer payloads (e.g., recorder.js, tab-gtm.js) and described evasion logic that attempts to avoid execution when site administrators are present (e.g., checking the DOM for WordPress’ wpadminbar). The infrastructure analysis also linked parts of the campaign to a domain associated with the sanctioned bulletproof hosting ecosystem around Stark Industries / PQ.Hosting, which has been described as rebranding to THE[.]Hosting under WorkTitans B.V., consistent with sanctions-evasion behavior; researchers emphasized that weak third-party script governance on payment pages remains a key enabling factor for this type of long-lived skimming operation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Silent Push disclosed that the operation had been active since early 2022 and described its malicious domain network, skimmer behavior, and data theft methods affecting multiple major payment brands. The researchers also linked supporting infrastructure to Stark Industries/PQ.Hosting, which they said had rebranded to THE.Hosting under WorkTitans B.V.
The campaign used highly obfuscated JavaScript on compromised WooCommerce and Stripe checkout flows, replacing legitimate payment forms with fake ones to capture card details before showing an error. The malware also used conditional activation, self-removal when the WordPress admin bar was detected, and anti-repeat logic to reduce detection.
A large-scale web skimming operation became active by January 2022, compromising online checkout pages to steal payment card and personal data from shoppers. The campaign targeted merchants, payment portals, and third-party payment processors tied to major card networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.