Published on 12/21/2023 – Last Updated on 12/22/2023 by OTC
One of our analysts recently found an interesting malicious plugin injected into a WordPress / WooCommerce ecommerce website which both creates and conceals a bogus administrator user. It was also found injecting sophisticated credit card skimming JavaScript into the website’s checkout page. This plugin includes an interesting sample of malicious code which goes to great lengths to conceal itself from the website owner.
In this post, we’ll review how the malware worked as well as how ecommerce website owners can protect themselves from such attacks.
Comments