Magecart Campaign Exploits Stripe for Credit Card Theft

Magecart Campaign Exploits Stripe for Credit Card Theft

First seen 5 Jun 2026, 17:26 UTC BleepingcomputerGbhackersCybersecuritynews 82% similarity 67.5

Article Content

Browse articles
ThreatCluster

A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into checkout pages, making it difficult for security measures to detect. The skimmer targets Magento/Adobe Commerce platforms, aiming to steal sensitive payment data including credit card numbers, expiration dates, CVV codes, and customer details. Once collected, the stolen data is stored in Stripe customer metadata, effectively using Stripe as a command and control server. This operation has been active since at least December 24, 2025, and researchers from Sansec have identified a variant that uses Google Firestore for data storage. The campaign poses a significant risk to online retailers and their customers as it exploits trusted services to evade detection.

Key Points: • Magecart campaign uses Stripe's API to host a JavaScript skimmer for credit card theft. • Malicious code is injected via Google Tag Manager, targeting Magento/Adobe Commerce checkout pages. • Stolen payment data is stored in Stripe customer metadata, making detection challenging.

ThreatCluster AI

Timeline

2025-12-24
Magecart operation initiated
The malicious Stripe customer record was created, indicating the start of the campaign.
BleepingComputer
2026-06-04
Campaign details published
Sansec researchers disclosed the Magecart campaign's methods and impact, highlighting the use of Stripe and Google Tag Manager.
BleepingComputer
2026-06-05
Further analysis released
Gbhackers reported on the Magecart campaign, emphasizing its use of legitimate cloud services for evasion.
Gbhackers

Community

Browse all →