Skip to content

New Magecart Attack Abuses Stripe as Malware C2

Gbhackers Mayura Kathir June 5, 2026

A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer metadata and delivering it to victim checkouts via Google Tag Manager. The combination makes Stripe both the command server for arbitrary code and the durable exfiltration sink for stolen card data, using domains (googletagmanager.com […]

Extracted Entities