Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Meta’s Muse Is Better at Surveilling Than Helping Me

    September 20, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Meta’s Muse Is Better at Surveilling Than Helping Me
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4
    • This Week’s Awesome Tech Stories From Around the Web (Through September 19)
    • Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
    • Mathematicians Hate AI. They Can’t Quit It
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Credit card theft campaign abuses Stripe to host stolen payment info
    Cybersecurity

    Credit card theft campaign abuses Stripe to host stolen payment info

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 7, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Credit card theft campaign abuses Stripe to host stolen payment info
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new Magecart campaign is using Stripe’s API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages.

    The entire malicious activity relies on Google Tag Manager and Stripe domains – googletagmanager.com and api.stripe.com – that are trusted implicitly by online stores.

    The new malware family was discovered by researchers at ecommerce security company Sansec, who found that the malicious code is loaded from a Google Tag Manager (GTM) container and executes on every page that loads it.

    “Both the payload and the stolen cards move through api.stripe.com. Stores allow that domain by default, so the skimmer slips past Content Security Policy rules and network filters that would otherwise flag traffic to an unknown skimmer domain,” Sansec says.

    GTM is a management system that allows website owners to add and manage scripts used for analytics, ads, and tracking, without modifying the site’s source code.

    Stripe is a payment processing platform widely used by online stores to accept credit cards, manage customer orders, and handle billing.

    According to Sansec, the malicious code is embedded in legitimate-looking GTM containers, which activate when a shopper reaches a checkout page, queuing Stripe’s API for a specific customer record, cus_TfFjAAZQNOYENR, in this case

    From the metadata fields of the record, it reads JavaScript code that it reassembles and then executes using new Function().

    The card skimmer targets Magento/Adobe Commerce checkout pages and attempts to capture payment data (credit card number, expiration date, CVV code, customer name) as well as billing and email addresses, and phone number.

    Card skimmer code
    Source: Sansec

    The stolen data is concatenated into a single string, obfuscated using the XOR operation, and stored locally instead of immediately exfiltrated.

    Retrieving the data is done through a separate routine, which executes right after a page load and every minute after, by splitting the data blob in half, creating a new Stripe customer object, and storing the stolen data in metadata fields.

    Every stolen payment card becomes a fake customer record in the attacker’s Stripe account, turning Stripe into a storage backend for stolen data.

    Once the data is copied, the local file is wiped to eliminate traces of the attack and prevent duplicate uploads.

    Data exfiltration routine
    Source: Sansec

    Sansec also discovered a variant of the attack where Google Firestore, a cloud database service for data storage and real-time retrieval, is used instead of Stripe.

    In that version of the campaign, the payload is retrieved from a Firestore document named tracking/captcha in a project called braintree-payment-app. The stolen data is stored in a different localStorage key (_d_data_customer_).

    The names of the document and the project help the malware blend in with legitimate payment and bot-protection traffic.

    The Stripe customer record containing the skimmer was reportedly created on December 24, 2025, suggesting that the operation may have been active since at least that date.

    Customers can protect themselves from such risks by using one-time virtual cards with set limits.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    abuses Campaign Card credit Host info Payment Stolen Stripe theft
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    OpenAI Claims Another Huge Mathematical Result Amid Fights Over Credit, Ethics, and Privacy

    September 12, 2026

    When AI designs a drug, who gets the credit?

    August 21, 2026

    The Download: threats from space mirrors and credit for AI drugs

    August 21, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Meta’s Muse Is Better at Surveilling Than Helping Me
    • It’s Donald Trump Versus MAGA on Data Centers
    • Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons
    • Napster Is Back, and It Wants to Digitally Clone Teachers
    • Join the WIRED World Fair in Miami on November 4

    Meta’s Muse Is Better at Surveilling Than Helping Me

    September 20, 2026

    It’s Donald Trump Versus MAGA on Data Centers

    September 20, 2026

    Why AI Isn’t Likely to Wipe Out Humanity With Bioweapons

    September 20, 2026

    Napster Is Back, and It Wants to Digitally Clone Teachers

    September 19, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.