Hackers embed credit card stealers in miniature SVG images on e-commerce sites

techradar.com

Hackers hid credit card stealing malware within miniature SVG images on nearly 100 e-commerce sites. The malicious code was embedded in 1x1 pixel SVG elements with an 'onload' handler, executing the skimmer payload directly within the website's HTML. This technique likely exploited the PolyShell vulnerability in Magento, a flaw discovered in March 2026, allowing attackers to steal data via a fake "Secure Checkout" overlay.


With a significance score of 2.5, this news ranks in the top 18% of today's 33456 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers: