Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files

released on 2020-06-29 @ 04:39:54 PM
Malwarebytes Labs found skimming code hidden within the metadata of an image file (a form of steganography) and surreptitiously loaded by compromised online stores. This scheme would not be complete without yet another interesting variation to exfiltrate stolen credit card data. Once again, criminals used the disguise of an image file to collect their loot. During this research, we came across the source code for this skimmer which confirmed what we were seeing via client-side JavaScript. We also identified connections to other scripts based on various data points.