Dec. 7, 2023, 8:25 p.m. | Denis Sinegubko

Sucuri Blog blog.sucuri.net

Hackers like Google Tag Manager: millions of sites use it, and they can inject custom scripts and HTML code via a script from the highly trusted domain googletagmanager.com. In order to create a new container and abuse Google Tag Manager, all they need is a Google account (and we all know how easy it is to get one).


Given the widespread use of GTM and the inherent trust websites put in scripts from Google, this tactic presents a significant …

abuse account code container credit card stealers domain domains ecommerce security found google google account google tag google tag manager hacked websites hackers html inject magecart magento security malware manager new domains obfuscation order script scripts tag veteran website malware infections website security

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Lead Technical Product Manager - Threat Protection

@ Mastercard | Remote - United Kingdom

Data Privacy Officer

@ Banco Popular | San Juan, PR

GRC Security Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City

Cyber Security Engineer

@ ASSYSTEM | Warrington, United Kingdom

Privacy Engineer, Technical Audit

@ Meta | Menlo Park, CA