Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment data.



  • Attackers abuse Stripe API via Google Tag Manager
  • Malware steals payment data from compromised Magento sites
  • Details of stolen cards exfiltrated via api.stripe.com

Cybercriminals have turned Stripe into a malware hosting platform, in a new attack that steals payment information from online shoppers. This is according to cybersecurity researchers Sansec, who discovered the campaign earlier this week.

Sansec says the attackers managed to compromise certain Magento/Adobe Commerce store websites and add a malicious Google Tag Manager (GTM) container.

Leave a Comment

Your email address will not be published. Required fields are marked *