AppSec · 117 giorni fa
Gli allowlist dei domini e le regole CSP falliscono quando lo skimmer vive all’interno di servizi che i negozi già si fidano. Qui, Google Tag Manager carica il codice e api.stripe.com trasporta i dati rubati, quindi il traffico sembra una normale infrastruttura di checkout invece di un attacco bloccato.
1 fonte che coprono questa storia
Credit card theft campaign abuses Stripe to host stolen payment info
A new Magecart campaign is using Stripe's API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages.
Part of the PlainSec briefing for 2026-06-05