RESOURCES / THREAT RESEARCH

Third Magecart Attack Returns to Major U.S. Brand Stores

Source Defense Research identified a third distinct payment-skimming attack affecting the same e-commerce ecosystem since the second half of 2024, this time with malicious JavaScript stored directly on official brand merchandise websites. The September 2026 campaign affected stores associated with major U.S. automotive brands and a major American aviation manufacturer, but the malicious activity was removed within approximately two to five days after Source Defense reported it.

Unlike the previous campaign, which concealed malicious code within trusted Google Tag Manager infrastructure, the latest skimmer was delivered from the affected websites themselves. It monitored checkout activity, collected payment-card and customer information, and sent the stolen data to a newly registered domain designed to resemble legitimate checkout infrastructure.

Attack details

This is the third payment-skimming incident Source Defense Research has documented in this storefront ecosystem since the second half of 2024.

The first known incident used an external malicious domain to deliver its code. A second campaign, active by January 2, 2026, used Google Tag Manager to conceal malicious code and an attacker-controlled Google Analytics account to receive stolen checkout information. Since the affected websites legitimately used these Google services, security policies allowing trusted Google domains could also permit the malicious activity. That campaign remained capable of stealing customer information for approximately four months before it was removed.

The September 2026 attack changed the delivery method again. The malicious JavaScript was stored directly on the affected websites, allowing it to execute as part of the storefront’s own resources rather than being loaded from an unfamiliar external source.

Once running in the browser, the skimmer monitored customer input, checkout clicks, form submissions, and changes to the payment page. It was designed to collect payment-card numbers, CVV or CVC security codes, expiration dates, cardholder names, email addresses, telephone numbers, and shipping and billing information.

The monitoring began before the customer completed the order. That meant sensitive information could potentially be captured even if the legitimate transaction failed or the customer abandoned checkout.

The stolen information was obfuscated and sent to checkout-cdn[.]com. The domain had been registered shortly before Source Defense discovered the attack and was not listed by the reputation sources checked at the time. Its name appeared designed to resemble legitimate checkout or content-delivery infrastructure.

A controlled test confirmed that the skimmer could collect and transmit a complete test checkout record.

Further investigation also expanded the known victim set. What initially appeared to affect official merchandise stores associated with major U.S. automotive manufacturers was also found on an official merchandise website belonging to a major American aviation manufacturer.

The affected storefronts shared a common e-commerce management relationship. This makes shared infrastructure, administrative access, application code, or deployment processes relevant areas for investigation, although the available evidence does not establish the precise point of compromise.

Source Defense reported the incident to the relevant organizations and provided technical evidence to support investigation and containment. The malicious activity was subsequently removed from the affected websites Source Defense was monitoring.

Available evidence indicates that the September campaign remained active for approximately two to five days, depending on the storefront. That is substantially shorter than the roughly four-month exposure period observed during the previous campaign.

How Source Defense protects you

Payment skimmers operate inside the customer’s browser, at the moment sensitive information is entered. Source Defense provides runtime visibility and protection at that point of interaction by evaluating what scripts are doing in the browser and applying policies accordingly.

In an attack like this, Source Defense can identify behavior involving access to PCI data and PII, along with suspicious attempts to send collected information elsewhere. This behavior-based approach matters when attackers change file locations, domains, or delivery methods.

The September campaign demonstrates that a malicious file does not need to arrive from an obviously suspicious external source to create risk. Source Defense evaluates browser activity based on what code actually does, helping organizations protect sensitive checkout data even as attackers rotate infrastructure and alter how their skimmers are delivered.

Key takeaways

Three payment-skimming campaigns have now affected the same e-commerce ecosystem since the second half of 2024, and each used a different technique. The latest attack moved malicious code onto the affected storefronts themselves and used a newly registered domain for data exfiltration. The evidence does not establish that the same attacker was responsible for all three incidents, but it does show repeated compromise and continued changes in attack methods.

The rapid removal of the latest campaign reduced its potential exposure window from months to days. Even so, a short-lived skimmer can still capture highly sensitive information because it operates precisely when customers enter payment and personal data.

Content Security Policy (CSP) and Subresource Integrity (SRI) are browser-enforced controls focused on permitted sources, policies, or resource integrity. They can play an important role, but this campaign shows why source and integrity checks alone do not provide the full picture when malicious code is delivered from an allowed location or when attackers continuously change infrastructure.

WAFs, firewalls, backend logs, and server-side monitoring operate outside the shopper’s browser. They do not provide the same view into how JavaScript interacts with sensitive fields during a live browsing session.

Fixed indicators also age quickly. Across these incidents, domains, delivery locations, and supporting services changed repeatedly. Source Defense evaluates and controls script behavior at runtime, helping organizations maintain protection even when attackers replace domains, move files, or change delivery methods.

The recurring lesson is clear: stopping browser-based payment theft requires visibility into what JavaScript actually does with customer data, not just where that code came from.

Related Reads

Source Defense
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.