Hackers misused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment information


  • Attackers abuse the Stripe API via Google Tag Manager
  • Malware skims payment data from compromised Magento sites
  • Stolen card information exfiltrated through api.stripe.com

Cybercriminals have turned Stripe into a malware hosting platform in a new attack that steals people’s payment information from online shoppers. This is according to cyber security researchers Sansec, who discovered the campaign earlier this week.

Sansec says the attackers managed to compromise certain Magento/Adobe Commerce store websites and add a malicious Google Tag Manager (GTM) container.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top