The HexMage Magecart campaign has compromised more than 40 e-commerce storefronts across at least 15 countries, primarily targeting WooCommerce sites but also affecting PrestaShop, Magento, and standard WordPress installations. Attackers first compromise the merchant’s server and inject a lightweight JavaScript loader into checkout pages, disguising it as a fake Google Tag Manager block. The loader uses Ethereum’s Sepolia testnet and attacker-controlled smart contracts to retrieve the hostname of the final payment-skimming script. The campaign uses EtherHiding, allowing malicious infrastructure to be stored and dynamically updated through blockchain smart contracts. The final skimmer captures payment-card numbers, expiry dates, CVVs, cardholder names, billing emails, and other checkout information before encoding and exfiltrating it. The malware is customized for multiple payment gateways, including Stripe, PayPal, ePay, PhonePe, and HyperPay. Researchers identified 156 related smart contracts associated with the attacker wallet by August 23, 2026. Organizations should inspect checkout pages for unauthorized JavaScript, Web3 libraries, Ethereum RPC connections, and fake GTM code. Website servers, administrator accounts, plugins, and payment templates should also be audited for compromise. Strong Content Security Policy controls should restrict unapproved scripts and outbound connections, while continuous monitoring should detect unexpected changes to checkout code. Since the article does not identify a specific CVE, CVE-IDs are not applicable/mentioned for this campaign.
Gyazo, the cloud-based screenshot and screen-recording platform operated by Helpfeel, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026...
Plugin4Shell is a high-severity supply-chain vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. T...
A newly identified Windows malware framework dubbed MovieReaper is being distributed through compromised torrent infrastructure and fake downloads of popular movies. Security resea...