Trusted Checkout Domains Hide Card Skimmer

Domain allowlists and CSP rules fail when the skimmer lives inside services stores already trust. Here, Google Tag Manager loads the code and api.stripe.com carries the stolen data, so the traffic looks like normal checkout infrastructure instead of a blocked attack. Sansec says the Magecart campaign has been active since Dec. 24 and targets Magento and Adobe Commerce checkout pages. The skimmer runs from a GTM container, steals card data and billing details, and stores the loot as fake Stripe customer records through api.stripe.com; a variant uses Google Firestore instead. The risk is broader than one campaign. Any checkout page that lets third-party tags or embedded payment scripts run can hide theft inside permitted SaaS traffic, which makes domain-based filtering a weak signal for payment compromise.

Part of the PlainSec briefing for 2026-06-05

Sources