Security researchers reported Magecart payment-card skimming infrastructure that abuses trusted services to conceal command-and-control and payload delivery. Sansec identified a campaign using the Stripe API as a malware command server, while Confiant documented the HexMage cluster using EtherHiding on Ethereum's Sepolia testnet to obtain the hostname serving its skimmer payloads.
HexMage compromises legitimate e-commerce sites through server-side JavaScript injected to resemble a Google Tag Manager block. The code loads ethers.js, queries an attacker-controlled smart contract, and retrieves a payment overlay tailored to the merchant's gateway; it captures card and billing data, permits the real transaction to complete, restores the checkout DOM, and avoids execution for logged-in WordPress administrators. Confiant observed more than 40 affected sites across at least 15 countries from about April 2026 and linked 20 staging contracts to a wallet that deployed at least 144 contracts between March and July 2026.

Get the actors, campaigns, and ATT&CK mapping behind it.
8 events from the most recent confirmed update back to the earliest known activity.
By 23 August, the wallet associated with HexMage staging contracts had deployed 156 contracts on Ethereum Sepolia.
Between 28 March and 21 July, the shared HexMage owner wallet deployed 144 matching Sepolia staging contracts.
HexMage compromised Danish WooCommerce retailer marinexperten.dk and replaced its ePay Denmark payment interface with an inline fraudulent card-entry form.
From 19 May, newly deployed HexMage contracts used encrypted salt:iv:ciphertext hostname envelopes. The browser-side loader decrypted the values using PBKDF2-derived key material and AES-GCM.
HexMage contracts deployed through 29 April used Base64-encoded plaintext hostnames to identify skimmer-delivery infrastructure.
The HexMage Magecart campaign was observed compromising legitimate e-commerce storefronts from approximately April 2026. It ultimately affected more than 40 sites in at least 15 countries, primarily WooCommerce stores.
The wallet 0x88361C914Bb0942da9a1b7Bb396a7513C1917aee began deploying matching HexMage smart contracts on the Ethereum Sepolia testnet. The contracts provided a publicly callable getText() function used to supply skimmer-delivery hostnames.
Confiant identified HexMage's fake Google Tag Manager JavaScript loader, which retrieves ethers.js and queries Sepolia smart contracts for disposable skimmer-delivery domains. The report also documented payment-form overlay and data-exfiltration behavior, a blockchain-free encoded-URL variant, and delivery and collection domains used against marinexperten.dk and other stores.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 80 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourceblog.confiant.com
Open sourcesansec.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.