Hundreds of e-commerce sites hacked in supply-chain attack
image via Ars Technica
May 5, 2025, 7:05 PM
- •A supply-chain attack has compromised three software providers (Tigren, Magesolution, and Meetanshi) and potentially a fourth (Weltpixel), infecting at least 500 e-commerce sites, including one owned by a $40 billion multinational company.
- •The malware, dormant for six years, now executes malicious code in visitors' browsers, enabling the theft of payment card information and sensitive data.
- •The backdoor allows attackers full remote code execution, leading to the injection of skimming software (Magecart) that steals payment information.
- •The affected providers are still distributing backdoored software and the method by which the malware remained undetected for so long is under investigation.
A supply-chain attack has infected at least 500 e-commerce sites with malware that executes malicious code within visitors' browsers, enabling attackers to steal payment information and other sensitive data. The attack, which started in April, targets software from Tigren, Magesolution, and Meetanshi, and potentially Weltpixel. The compromised software has backdoors that give attackers remote code execution, allowing them to inject skimming software. The malware, which remained dormant for six years, is now active, and remediation efforts are limited.
Entities Mentioned
Sansec
Topics Covered
Biz & ITSecuritybackdoorsmagentomalwaresupply chain attack
Comments (0)
No comments yet.