May 21, 2020 By Shane Schick 2 min read

A Magento plugin vulnerability that dates back at least three years could allow e-skimming attacks on unsuspecting online shoppers, the FBI warns.

In an alert sent out earlier this month, the FBI said hackers are using the exploit to take over e-commerce stores powered by Magento software and steal payment card data from customers.

The attacks work by embedding malware into Magento Mass Import, also known as MAGMI. The cross-site scripting bug allows cybercriminals to infect an online store’s HTML code to conduct e-skimming without being noticed.

How Malware Targets MAMGI

Any time someone buys from an e-commerce store using the Magento plugin, hackers can record details of the financial transaction after modifying the site’s PHP and JavaScript files.

The FBI said those who know how to exploit the bug are also planting web shells to allow them access to the same store again. While an e-commerce shop owner might not be aware, the stolen data is sent to the cybercriminals’ command-and-control (C&C) server after it has been encoded in Base64 format and disguised within a JPEG file.

Besides payment card data, the FBI said hackers are able to collect several pieces of personally identifiable information (PII). This includes customers’ names, physical addresses and telephone numbers.

One thing that may affect the scope of the threat is the fact that MAGMI only works with early versions of Magento. Some of these, such as Magento 1.x branch, are scheduled to reach end of life by next month. This means sites running that version won’t continue to receive security updates from the vendor.

End the Opportunity for E-Skimming via MAGMI

The FBI’s recommendations for mitigating the risk of the attacks include updating to more recent versions of Magento and making sure the systems are properly patched and up to date.

E-commerce store owners could also be in a better position to detect an attack by having a managed firewall service that can log potential problems and block unauthorized users.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today