Tech »  Topic »  Thousands of ecommerce sites at risk after popular CMS targeted by malware attack — here's what you need to know

Thousands of ecommerce sites at risk after popular CMS targeted by malware attack — here's what you need to know


(Image credit: sarayut Thaneerat/ via Getty Images)
  • OpenCart websites were silently injected with malware that mimics trusted tracking scripts
  • Script hides in analytics tags and quietly swaps real payment forms for fake ones
  • Obfuscated JavaScript allowed attackers to slip past detection and launch credential theft in real time

A new Magecart-style attack has raised concerns across the cybersecurity landscape, targeting ecommerce websites which rely on the OpenCart CMS.

The attackers injected malicious JavaScript into landing pages, cleverly hiding their payload among legitimate analytics and marketing tags such as Facebook Pixel, Meta Pixel, and Google Tag Manager.

Exepers from c/side, a cybersecurity firm that monitors third-party scripts and web assets to detect and prevent client-side attacks, says the injected code resembles a standard tag snippet, but its behavior tells a different story.

Hackers are using Google.com to deliver malware by bypassing antivirus software. Here's how to stay safe ...
Copyright of this story solely belongs to techradar.com . To see the full text click HERE