Skip to content

MageCart

Magecart is an umbrella term for multiple financially motivated threat groups and the JavaScript-based web skimming malware they deploy against e-commerce environments.

Profile source: Mallory opens in a new tab

MageCart

Family profile

Magecart is an umbrella term for multiple financially motivated threat groups and the JavaScript-based web skimming malware they deploy against e-commerce environments. Magecart operations compromise online stores, payment portals, and related checkout infrastructure by injecting malicious client-side code into payment pages, third-party tags, locally hosted libraries, plugins, themes, or other web assets. The malware is designed to capture payment card data and associated customer information entered during checkout, including card numbers, expiration dates, CVVs, names, billing addresses, email addresses, phone numbers, and other form data, then exfiltrate that information to attacker-controlled infrastructure.

Magecart activity has affected a wide range of platforms and ecosystems, including Magento and Adobe Commerce, WooCommerce on WordPress, PrestaShop, Volusion, X-Cart, and government payment portals such as Click2Gov. Infection vectors include direct compromise of merchant websites, tampering with checkout plugins, abuse of public AJAX endpoints, modification of legitimate JavaScript libraries, insertion into Google Tag Manager containers, abuse of trusted third-party infrastructure such as Stripe and GitHub, and hybrid client-side/server-side skimming designs that stage stolen data through the victim site before forwarding it externally. Some campaigns also hide payloads in benign-looking assets such as PNG images or disguise skimmers as analytics, tag-management, or CDN resources.

Observed Magecart variants commonly activate only on checkout-related pages, hook payment form events, inject fake payment forms, overlay legitimate payment interfaces, or dynamically map and harvest input fields. Many samples use obfuscation, anti-debugging, integrity checks, local or session storage, deduplication logic, delayed exfiltration, or self-removal to evade detection and prolong dwell time. Exfiltration methods have included HTTP POST, image beacons, navigator.sendBeacon, WebSocket communications, same-site staging scripts, and abuse of external service backends.

Magecart is primarily associated with payment-card theft and broader e-skimming fraud rather than destructive or disruptive objectives. Stolen data is typically monetized through carding marketplaces and related fraud ecosystems. Public reporting has linked specific clusters and campaigns to multiple distinct Magecart groups, including activity associated with FIN6 in some cases, but the term itself remains a collective label rather than a single malware family or actor. The principal targets are online retailers and any organization operating web-based payment workflows, with victims ranging from small merchants to major retail brands and public-sector payment sites.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 26, 2026
Last activity
Sep 1, 2026
Feed role
C2 / Distribution
Host form
0 IP / 54 hostnames

Leading locations

  • US32
  • CY3
  • FR3
  • ID2
  • TR2
  • BE1
  • CH1
  • DE1
  • ES1
  • IT1
  • JP1
  • NL1

Leading providers

  • Cloudflare, Inc.12
  • Hostinger International Limited8
  • Oracle Corporation4
  • Cloudflare London, LLC3
  • GoDaddy.com, LLC2
  • GoDaddy.com, LLC2

Infrastructure traits

  • Hosting 53
  • Anycast 23

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
FIN6

We discovered that the online credit card skimming attack known as Magecart or E-Skimming was actively operating on 3,126 online shops.

Exploited software

Vulnerabilities linked to MageCart

2 CVEs

MITRE ATT&CK

MageCart in ATT&CK

16 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.