Skip to content
ThreatCluster

New Magecart Attack Targets E-commerce with Malicious JavaScript

First seen 22 Jan 2026, 02:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A new Magecart-style attack is targeting e-commerce websites by injecting malicious JavaScript designed to steal payment information during checkout. The attack uses obfuscated code hosted at cc-analytics[.]com/app.js to intercept sensitive data entered by customers. Online shoppers are at risk as this campaign compromises the security of their payment details.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Magecart in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed