{"id":980695,"date":"2022-02-11T06:15:24","date_gmt":"2022-02-11T11:15:24","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=980695"},"modified":"2022-02-11T06:15:24","modified_gmt":"2022-02-11T11:15:24","slug":"hundreds-of-e-commerce-sites-booby-trapped-with-payment-card-skimming-malware","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=980695","title":{"rendered":"Hundreds of e-commerce sites booby-trapped with payment card skimming malware"},"content":{"rendered":"<div id=\"rss-wrap\">\n<figure class=\"intro-image intro-left\">\n  <img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2022\/02\/payment-card-online-800x534-1.jpe\" alt=\"Stock photo of a woman using a laptop and a credit card to make a purchase.\" \/><\/p>\n<p class=\"caption\" style=\"font-size:0.8em\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2022\/02\/payment-card-online.jpeg\" class=\"enlarge-link\" data-height=\"667\" data-width=\"1000\">Enlarge<\/a> (credit: <a rel=\"nofollow\" class=\"caption-link\" href=\"https:\/\/www.gettyimages.com\/\">Getty Images<\/a>)<\/p>\n<\/figure>\n<div><a name=\"page-1\" \/><\/div>\n<p>About 500 e-commerce websites were recently found to be compromised by hackers who installed a credit card skimmer that surreptitiously stole sensitive data when visitors attempted to make a purchase.<\/p>\n<p>A <a href=\"https:\/\/sansec.io\/research\/naturalfreshmall-mass-hack\">report<\/a> published on Tuesday is only the latest one involving Magecart, an umbrella term given to competing crime groups that infect e-commerce sites with skimmers. Over the past few years, <a href=\"https:\/\/arstechnica.com\/information-technology\/2019\/03\/a-new-rash-of-highly-covert-card-skimming-malware-infects-ecommerce-sites\/\">thousands<\/a> of <a href=\"https:\/\/arstechnica.com\/information-technology\/2018\/11\/sign-of-the-times-payment-card-skimmers-go-head-to-head-on-e-commerce-site\/\">sites<\/a> have been <a href=\"https:\/\/arstechnica.com\/information-technology\/2018\/09\/newegg-hit-by-credit-card-stealing-code-injected-into-shopping-code\/\">hit<\/a> by exploits that cause them to run malicious code. When visitors enter payment card details during purchase, the code sends them to attacker-controlled servers.<\/p>\n<h2>Fraud courtesy of Naturalfreshmall[.]com<\/h2>\n<p>Sansec, the security firm that discovered the latest batch of infections, said the compromised sites were all loading malicious scripts hosted at the domain naturalfreshmall[.]com.<\/p>\n<\/div>\n<p><a href=\"https:\/\/arstechnica.com\/?p=1833417#p3\">Read 8 remaining paragraphs<\/a> | <a href=\"https:\/\/arstechnica.com\/?p=1833417&amp;comments=1\">Comments<\/a><\/p>\n<div class=\"feedflare\">\n<a href=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?a=foTzXkfPiQk:K65rvRtKwfI:V_sGLiPBpWU\"><img decoding=\"async\" src=\"\" border=\"0\" \/><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?a=foTzXkfPiQk:K65rvRtKwfI:F7zBnMyn0Lo\"><img decoding=\"async\" src=\"\" border=\"0\" \/><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?a=foTzXkfPiQk:K65rvRtKwfI:qj6IDK7rITs\"><img decoding=\"async\" src=\"\" border=\"0\" \/><\/a> <a href=\"http:\/\/feeds.feedburner.com\/~ff\/arstechnica\/index?a=foTzXkfPiQk:K65rvRtKwfI:yIl2AUoC8zA\"><img decoding=\"async\" src=\"\" border=\"0\" \/><\/a>\n<\/div>\n<p>&#013;<br \/>\n&#013;<br \/>\nSource: Ars Technica &#8211; <a href=\"https:\/\/arstechnica.com\/?p=1833417\" target=\"_blank\" rel=\"noopener\">Hundreds of e-commerce sites booby-trapped with payment card skimming malware<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enlarge (credit: Getty Images) About 500 e-commerce websites were recently found to be compromised by hackers who installed a credit card skimmer that surreptitiously stole sensitive data when visitors attempted to make a purchase. A report published on Tuesday is &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=980695\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":980696,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[27,110],"tags":[73],"class_list":["post-980695","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ars-technica","category-unfiltered-rss","tag-ars-technica"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/980695","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=980695"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/980695\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/980696"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=980695"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=980695"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=980695"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}