Researchers detailed a Magecart-style web skimmer planted in a compromised online store, where malicious JavaScript injected a fake payment form into the checkout process, captured card data as customers typed it, and exfiltrated the information to an attacker-controlled server disguised as an image request. The skimmer used anti-debugging, adaptive field mapping, and localStorage persistence to evade detection and maintain access, with reported indicators including gstatis.co and 185.215.113.111.
Separate reporting on a major Japanese case described a similar web skimming intrusion in which attackers embedded heavily obfuscated code into an existing site JavaScript file, potentially exposing data from more than 100,000 records. Analysts said Content Security Policy (CSP) would not have stopped delivery of the tampered first-party script, but could have blocked exfiltration to www.javascriptworld.xyz/isSafe.php, underscoring that digital skimming attacks increasingly target payment applications by stealing data in the browser rather than breaching backend databases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Pi Mobile activated its incident response process, engaged a third-party forensic firm, and reported the matter to regulators. The company said it would notify affected users once the scope of any exposure is confirmed.
Taiwan’s Administration for Digital Industries opened an inspection under the Personal Data Protection Act in response to the Pi Mobile breach claim. The regulator also warned that stolen personal data is often abused by fraud syndicates.
PChome stated that its preliminary review found no intrusion affecting its main website or core systems. The company said the alleged incident remained under investigation.
The hacker group Settra claimed it had breached Pi Mobile Technology, a subsidiary of PChome Online, and stolen internal documents and user data. The claim was reported by Taiwan News and prompted scrutiny of the alleged incident.
A recent incident in Japan involved a web skimmer on an e-commerce site, with more than 100,000 records potentially affected. The malicious code was embedded into an existing JavaScript file on the website and was heavily obfuscated.
A Magecart-style web skimmer was found in a compromised webshop’s source code. The malicious JavaScript injected a fake payment form, captured payment data in real time, and exfiltrated it to gstatis.co at IP address 185.215.113.111 while using anti-debugging and persistence techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcesecurity.macnica.co.jp
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.