Magecart Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
12
occurrences
First Seen
January 21, 2026
Last Seen
July 10, 2026

Magecart is a malware family tracked across 7 threat clusters and 12 intelligence report mentions on ThreatCluster. First observed January 21, 2026; most recent activity July 10, 2026.

Related Threat Clusters

  • Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks

    A critical vulnerability in the Funnel Builder plugin for WooCommerce is being actively exploited, affecting over 40,000 websites. Attackers can inject malicious JavaScript into checkout pages without authentication,…

    5 articles · Updated May 15, 2026
  • Cybercriminals Exploit Trusted Tools for Malware Deployment

    Cybercriminals are increasingly using legitimate system tools like PowerShell and WMI to deploy malware, creating stealthy threats that evade traditional defenses. The ANY.RUN Q1 2026 Cyber Risk report highlights a…

    4 articles · Updated June 5, 2026
  • Magecart Campaign Targets 99 Magento Stores with SVG Skimmer

    A large-scale Magecart campaign has compromised 99 Magento e-commerce stores, utilizing an innovative evasion technique involving invisible SVG elements to inject credit card skimmers directly into checkout pages.…

    2 articles · Updated April 10, 2026
  • Magecart Campaign Exploits Stripe for Credit Card Theft

    A new Magecart campaign is leveraging Stripe's API to host a JavaScript skimmer that captures credit card information during online transactions. The attack utilizes Google Tag Manager to inject the malicious code into…

    3 articles · Updated June 5, 2026
  • Mastercard and Recorded Future Address Payment Fraud Ecosystem Challenges

    At RiskX Singapore 2026, Colin Mahony from Recorded Future and Aditi Sawhney from Mastercard discussed the evolving landscape of payment fraud. They emphasized that fraudulent transactions are the final outcome of a…

    2 articles · Updated July 9, 2026
  • Surge in eSkimming Attacks Challenges E-Commerce Security

    eSkimming attacks, also known as Magecart attacks, are increasingly targeting e-commerce websites, compromising payment card data during customer checkouts. These attacks involve injecting JavaScript into websites,…

    2 articles · Updated January 29, 2026
  • New Magecart Attack Targets E-commerce with Malicious JavaScript

    A new Magecart-style attack is targeting e-commerce websites by injecting malicious JavaScript designed to steal payment information during checkout. The attack uses obfuscated code hosted at cc-analytics[.]com/app.js…

    2 articles · Updated January 21, 2026

Recent Intelligence Reports

  • RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney — Recordedfuture · July 10, 2026
  • RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney — Recordedfuture · July 9, 2026
  • New Magecart Attack Turns Stripe into a Malware Command Server — Cybersecuritynews · June 5, 2026
  • Hackers Weaponize Trusted Tools to Deploy Notorious Malware — Gbhackers · June 5, 2026
  • New Magecart Attack Abuses Stripe as Malware C2 — Gbhackers · June 5, 2026
  • Credit card theft campaign abuses Stripe to host stolen payment info — Bleepingcomputer · June 4, 2026
  • Sansec detected the malicious activity — sansec.io · May 15, 2026
  • Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages — Cybersecuritynews · April 10, 2026

CVSS v3.1 Breakdown