Dec. 21, 2023, 8:49 p.m. | Ben Martin

Sucuri Blog blog.sucuri.net

One of our analysts recently found an interesting malicious plugin injected into a WordPress / WooCommerce ecommerce website which both creates and conceals a bogus administrator user. It was also found injecting sophisticated credit card skimming JavaScript into the website’s checkout page. This plugin includes an interesting sample of malicious code which goes to great lengths to conceal itself from the website owner.


In this post, we’ll review how the malware worked as well as how ecommerce website owners can …

analysts black hat tactics bogus card credit credit card credit card skimmer credit card stealers ecommerce ecommerce security found hacked websites javascript magecart malicious malicious plugin malware obfuscation page plugin sample skimmer skimming website website malware infections woocommerce wordpress wordpress plugin wordpress plugins and themes wordpress security

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, VA, Arlington (1550 Crystal Dr Suite 300) non-client

Invoice Compliance Reviewer

@ AC Disaster Consulting | Fort Myers, Florida, United States - Remote

Technical Program Manager II - Compliance

@ Microsoft | Redmond, Washington, United States

Head of U.S. Threat Intelligence / Senior Manager for Threat Intelligence

@ Moonshot | Washington, District of Columbia, United States

Customer Engineer, Security, Public Sector

@ Google | Virginia, USA; Illinois, USA