cognitive cybersecurity intelligence

News and Analysis

Search

Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft

Threat hunters have identified a rogue WordPress plugin capable of creating fake administrator users and injecting malicious JavaScript code to steal credit card information. The plugin, part of a Magecart campaign targeting e-commerce sites, replicates itself into must-use plugins, conceals its presence, and also includes an option to create hidden admin accounts. The campaign’s objective is to inject credit card-stealing malware into checkout pages and transmit the data to a hacker-controlled domain.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts