Infected WooCommerce Store — How Hackers Steal Payment Card Data
What is web skimming?
Web skimming (also known as Magecart) is an attack in which malicious JavaScript code is injected into a store’s website. It captures data customers enter in the payment form — card numbers, expiration dates, CVV codes — and sends it to the attacker’s server. The customer knows nothing about it, and the transaction proceeds normally.
This type of attack is particularly dangerous for WooCommerce stores that do not use a hosted payment form (e.g. Stripe Checkout, PayPal redirect), but instead implement the form directly on their website.
How can you recognize web skimming on WooCommerce?
- Customers report unauthorized card transactions after making a purchase in your store
- An unfamiliar JavaScript script from an external domain appears in the website’s code
- The
wp-content/themes/your-theme/functions.php file contains unfamiliar code that adds external scripts
Immediate steps if you suspect an attack
- Disable the payment module immediately — until it has been verified, do not allow customers to enter card details on your website
- Switch to payment by redirect (PayPal, Przelewy24, Stripe Checkout) — the data is then processed on the provider’s server, not yours
- Notify your payment provider that you suspect an attack
- Check and clean all JavaScript files in the theme and plugins
If you run a WooCommerce store, do not take chances — contact us. We specialize in e-commerce security.