Skip to content

Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages

Cybersecuritynews Abinaya April 10, 2026

A massive Magecart campaign compromising 99 Magento e-commerce stores using an innovative evasion technique. Discovered on April 7, 2026, the attack relies on invisible Scalable Vector Graphics (SVG) elements to inject credit card skimmers directly into checkout pages. This “double-tap” skimmer displays a highly convincing fake payment overlay before silently redirecting shoppers to the legitimate […]

Extracted Entities

Attack Types (1)

Campaigns (1)

Malware (1)

Platforms (1)