Last seven days
- First activity
- Aug 26, 2026
- Last activity
- Sep 1, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 54 hostnames
Magecart is an umbrella term for multiple financially motivated threat groups and the JavaScript-based web skimming malware they deploy against e-commerce environments.
Profile source: Mallory opens in a new tabMageCart
Magecart is an umbrella term for multiple financially motivated threat groups and the JavaScript-based web skimming malware they deploy against e-commerce environments. Magecart operations compromise online stores, payment portals, and related checkout infrastructure by injecting malicious client-side code into payment pages, third-party tags, locally hosted libraries, plugins, themes, or other web assets. The malware is designed to capture payment card data and associated customer information entered during checkout, including card numbers, expiration dates, CVVs, names, billing addresses, email addresses, phone numbers, and other form data, then exfiltrate that information to attacker-controlled infrastructure.
Magecart activity has affected a wide range of platforms and ecosystems, including Magento and Adobe Commerce, WooCommerce on WordPress, PrestaShop, Volusion, X-Cart, and government payment portals such as Click2Gov. Infection vectors include direct compromise of merchant websites, tampering with checkout plugins, abuse of public AJAX endpoints, modification of legitimate JavaScript libraries, insertion into Google Tag Manager containers, abuse of trusted third-party infrastructure such as Stripe and GitHub, and hybrid client-side/server-side skimming designs that stage stolen data through the victim site before forwarding it externally. Some campaigns also hide payloads in benign-looking assets such as PNG images or disguise skimmers as analytics, tag-management, or CDN resources.
Observed Magecart variants commonly activate only on checkout-related pages, hook payment form events, inject fake payment forms, overlay legitimate payment interfaces, or dynamically map and harvest input fields. Many samples use obfuscation, anti-debugging, integrity checks, local or session storage, deduplication logic, delayed exfiltration, or self-removal to evade detection and prolong dwell time. Exfiltration methods have included HTTP POST, image beacons, navigator.sendBeacon, WebSocket communications, same-site staging scripts, and abuse of external service backends.
Magecart is primarily associated with payment-card theft and broader e-skimming fraud rather than destructive or disruptive objectives. Stolen data is typically monetized through carding marketplaces and related fraud ecosystems. Public reporting has linked specific clusters and campaigns to multiple distinct Magecart groups, including activity associated with FIN6 in some cases, but the term itself remains a collective label rather than a single malware family or actor. The principal targets are online retailers and any organization operating web-based payment workflows, with victims ranging from small merchants to major retail brands and public-sector payment sites.
C2 tracking
Derp observations, rolling seven-day window
Samples
3b3a866c128619fe7c6a0b57323c610f00385188a37f8b444de1d72cc883aa62 71f9175499192a3e2c044cd3c06a99447bb9c7c78f715524c527e0d9dca48dfb 86687aab41ba84532de262cc3304dff696c3d73e0dc52043e2eb9b1207a0cae8 ce2a3511b4e81ea0e870765b08088c4750ecab82250d4626a607dec823d4d4b5 fb00945a60b6738541277037521fc21ad59fd3412e4188052b1bace0e97d06f1 Reported operators
We discovered that the online credit card skimming attack known as Magecart or E-Skimming was actively operating on 3,126 online shops.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.