Researchers found a compromised X-Cart e-commerce site running two separate payment skimmers: a basic server-side stealer and a more advanced client-side JavaScript skimmer. The server-side malware captured base64-encoded payment POST data and saved it to a fake .jpg file, while the browser-based skimmer validated that a credit card number was present before exfiltrating checkout data to attacker infrastructure. Analysts traced the X-Cart exfiltration path to metahtmlhead[.]com/folder/ip/zxc.php, with the destination assembled through DOM-based domain construction to hinder detection.
The JavaScript skimmer used layered obfuscation and an anti-debugging technique tied to wrapper-function length, forcing researchers to brute-force parts of the code to recover its behavior. A similar skimmer was later identified on a Magento 1.x site, using the same obfuscation style and a matching URL path structure but sending stolen payment data to winsiott[.]com/folder/ip/stt.php. The overlap in code design, evasion methods, and infrastructure indicates a broader web-skimming campaign targeting multiple e-commerce platforms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The domain metahtmlhead[.]com, later used by the X-Cart skimmer for exfiltration, was registered.
The domain winsiott[.]com, later used by a related Magento skimmer variant for data exfiltration, was registered.
PublicWWW identified additional infected sites hosting skimmer variations that used winsiott[.]com/folder/ip/stt.php. Sucuri SiteCheck detected those Magento infections as malware.magento_shoplift?199, indicating a broader campaign affecting multiple e-commerce sites.
Researchers identified a similar obfuscated JavaScript skimmer in the database of a Magento 1.x site. The malware shared the same decoding approach and code structure as the X-Cart variant, but exfiltrated data to winsiott[.]com/folder/ip/stt.php instead of deriving its domain from the DOM.
After brute-forcing the anti-debugging-dependent deobfuscation, analysts recovered the X-Cart skimmer logic and determined it built the exfiltration URL hxxps://metahtmlhead[.]com/folder/ip/zxc.php from the infected page's DOM.
Analysts found a compromised X-Cart e-commerce site containing both a server-side skimmer in payment/payment_swoosh_cc.php and an obfuscated client-side JavaScript skimmer in skin/common_files/check_cc_number_script.tpl. The server-side malware stored base64-encoded payment POST data in a fake .jpg file, while the client-side skimmer collected checkout form data and exfiltrated it after validating a credit card number was present.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.