A Magecart campaign compromised 3,126 online shops hosted on Volusion’s cloud e-commerce platform by tampering with the vnav.js JavaScript library used during checkout. The injected code loaded a second-stage skimmer from Google Storage, captured payment and personal information entered by customers, obfuscated the data, stored it in browser sessionStorage, and later exfiltrated it with HTTP POST requests to the lookalike domain volusion-cdn[.]com. Volusion said a limited subset of merchant customer information, including credit card data, was exposed.
Researchers linked the operation to Magecart Group 6 / FIN6 based on code and infrastructure overlaps with earlier e-skimming incidents involving British Airways and Newegg. The campaign reflected broader web-skimming tradecraft in which attackers inject malicious JavaScript into trusted payment pages to silently harvest checkout data at scale. Google removed the hosted malicious file, and Volusion acknowledged the compromise and said it had fixed the issue.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported that the e-skimming campaign targeting Volusion’s cloud e-commerce platform began on September 7, 2019. The operation ultimately affected 3,126 online shops by injecting malicious code into Volusion’s vnav.js library.
Trend Micro published technical analysis attributing the Volusion e-skimming operation to Magecart Group 6, also known as FIN6, based on code, infrastructure, and modus operandi similarities with earlier British Airways and Newegg attacks.
Volusion acknowledged the compromise and stated it resolved the issue within a few hours of notification. The company said a limited subset of merchant customer information, including credit card data, had been compromised.
After being contacted, Google removed the malicious JavaScript file hosted at a Google Storage URL that served as the second-stage skimmer. By the time of publication, this takedown had rendered the attack offline.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
blog.trendmicro.com
Open sourceriskiq.com
Open sourceriskiq.com
Open sourceniccs.us-cert.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.