AppSec · 102 days ago
Domain allowlists and CSP rules fail when the skimmer lives inside services stores already trust. Here, Google Tag Manager loads the code and api.stripe.com carries the stolen data, so the traffic looks like normal checkout infrastructure instead of a blocked attack.
Sansec says the Magecart campaign has been active since Dec. 24 and targets Magento and Adobe Commerce checkout pages. The skimmer runs from a GTM container, steals card data and billing details, and stores the loot as fake Stripe customer records through api.stripe.com; a variant uses Google Firestore instead.
The risk is broader than one campaign. Any checkout page that lets third-party tags or embedded payment scripts run can hide theft inside permitted SaaS traffic, which makes domain-based filtering a weak signal for payment compromise.
1 source covering this story
Credit card theft campaign abuses Stripe to host stolen payment info
A new Magecart campaign is using Stripe's API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages.
Part of the PlainSec briefing for 2026-06-05