Netskope Threat Labs

Magecart

ATP Sandbox Adv. HeuristicsNetskope IPS

Magecart refers to web skimming attacks where cyberattackers inject malicious JavaScript code into e-commerce websites to steal credit card information during checkout. Multiple crews operate under the name, and their intrusions range from compromised third-party scripts to direct breaches of major retailers, with several high profile airline and retail breaches attributed to the collective. Because the skimmers run in the victim's browser, the attacks bypass server side security entirely, and stolen card data flows straight to criminal marketplaces.

First seen
April 2023
Last seen
October 2026
Alert Name
Document-HTML.Infostealer.Magecart
Script-JS.Spyware.Magecart
Script-JS.Trojan.Magecart