Hackers hide credit card stealer in pixel-sized SVG on nearly 100 online stores

bleepingcomputer.com

Hackers are using a pixel-sized SVG image to hide credit card-stealing code on nearly 100 online stores. The malware is injected as a 1x1-pixel SVG element with an onload handler containing the encoded skimmer payload. This technique avoids external script references, making it harder to detect. The campaign likely exploits the PolyShell vulnerability. Adobe has not yet released a production fix for this flaw.


With a significance score of 3, this news ranks in the top 12% of today's 33415 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Hackers hide credit card stealer in pixel-sized SVG on nearly 100 online stores | News Minimalist