Magecart skimmer turns Stripe into a malware command server (sansec.io)
from cm0002@suppo.fi to cybersecurity@infosec.pub on 06 Jun 17:44
https://suppo.fi/post/12628981

#cybersecurity

threaded - newest

lurch@sh.itjust.works on 07 Jun 20:22 collapse

this is a shop owner account security problem. if someone can place the required malicious google tag on your site, they could also do whatever else they wanted. they could put any custom JS, for example. this stealer is just one of many payloads.