Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning
A sophisticated card-skimming operation targets e-commerce platforms by combining client-side payment skimming with EtherHiding techniques, staging payloads inside Ethereum blockchain smart-contract storage. The attackers compromise legitimate online storefronts, primarily WooCommerce installations along with PrestaShop, Magento, and WordPress sites, injecting a loader disguised as Google Tag Manager code. Over 40 impacted websites across fifteen countries have been observed since April 2026. The infrastructure includes 144 Sepolia contracts controlled by a single owner wallet, with 20 distinct contracts and corresponding skimmer-hosting domains identified in traffic. The malicious code is hidden server-side to appear as ordinary analytics plumbing while stealing credit card information from unsuspecting online shoppers.
Indicators of Compromise
- domain: styleranked.com
- domain: styleshort.com
- domain: styleussles.com
- domain: stylehailens.com
- domain: styleouresen.com
- domain: stylehersi.com
- domain: styleember.com
- domain: stylestyk.com
- domain: styleoutspin.com
- domain: stylegamingg.com
- domain: stylehelloman.com
- domain: stylegamagee.com
- domain: styletropik.com
- domain: styletimeset.com
- domain: stylerunningg.com
- domain: stylerightnoww.com
- domain: styleteleport.com
- domain: stylekanions.com
- domain: styleleftt.com
- domain: styleconnectorr.com
- domain: stylehipp.com
- domain: stylecaving.com
- domain: stylejunglee.com
- domain: stylehotrod.com
- domain: stylewify.com
- domain: styledupstep.com
- domain: styleanimal.com
- domain: streetfleshroyalgaming.top
- domain: styleferry.com
- domain: stylebonus.com
- domain: stylerazorr.com
- domain: styletumor.com
- domain: stylecholera.com
- domain: styletray.com
- domain: stylepenalty.com
- domain: stylekay.com
- domain: styleboosted.com
- domain: styledespair.com
- domain: smartpeoplework.info
- domain: blueoceanbreeze.org
- domain: sunnydaycoffees.net
- domain: nightstalkerwatch.top
- domain: ravenstonekeep.top
- domain: ashenravenfort.top
- domain: bloodboundcitadel.top
- domain: bloodthornkeep.top
- domain: brokenvelvetdream.top
- domain: darkflamewatch.top
- domain: frozennebularhy.top
- domain: frozenwildheart.top
- domain: grimwardens.com
- domain: shadowrunevail.top
- domain: voidravencitadel.com
- domain: voidwalkerforge.top
- domain: warmcoffeetime.top
Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning
Description
A sophisticated card-skimming operation targets e-commerce platforms by combining client-side payment skimming with EtherHiding techniques, staging payloads inside Ethereum blockchain smart-contract storage. The attackers compromise legitimate online storefronts, primarily WooCommerce installations along with PrestaShop, Magento, and WordPress sites, injecting a loader disguised as Google Tag Manager code. Over 40 impacted websites across fifteen countries have been observed since April 2026. The infrastructure includes 144 Sepolia contracts controlled by a single owner wallet, with 20 distinct contracts and corresponding skimmer-hosting domains identified in traffic. The malicious code is hidden server-side to appear as ordinary analytics plumbing while stealing credit card information from unsuspecting online shoppers.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- []
- Adversary
- null
- Pulse Id
- 6a9596d78e30aca83cac86db
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainstyleranked.com | — | |
domainstyleshort.com | — | |
domainstyleussles.com | — | |
domainstylehailens.com | — | |
domainstyleouresen.com | — | |
domainstylehersi.com | — | |
domainstyleember.com | — | |
domainstylestyk.com | — | |
domainstyleoutspin.com | — | |
domainstylegamingg.com | — | |
domainstylehelloman.com | — | |
domainstylegamagee.com | — | |
domainstyletropik.com | — | |
domainstyletimeset.com | — | |
domainstylerunningg.com | — | |
domainstylerightnoww.com | — | |
domainstyleteleport.com | — | |
domainstylekanions.com | — | |
domainstyleleftt.com | — | |
domainstyleconnectorr.com | — | |
domainstylehipp.com | — | |
domainstylecaving.com | — | |
domainstylejunglee.com | — | |
domainstylehotrod.com | — | |
domainstylewify.com | — | |
domainstyledupstep.com | — | |
domainstyleanimal.com | — | |
domainstreetfleshroyalgaming.top | — | |
domainstyleferry.com | — | |
domainstylebonus.com | — | |
domainstylerazorr.com | — | |
domainstyletumor.com | — | |
domainstylecholera.com | — | |
domainstyletray.com | — | |
domainstylepenalty.com | — | |
domainstylekay.com | — | |
domainstyleboosted.com | — | |
domainstyledespair.com | — | |
domainsmartpeoplework.info | — | |
domainblueoceanbreeze.org | — | |
domainsunnydaycoffees.net | — | |
domainnightstalkerwatch.top | — | |
domainravenstonekeep.top | — | |
domainashenravenfort.top | — | |
domainbloodboundcitadel.top | — | |
domainbloodthornkeep.top | — | |
domainbrokenvelvetdream.top | — | |
domaindarkflamewatch.top | — | |
domainfrozennebularhy.top | — | |
domainfrozenwildheart.top | — | |
domaingrimwardens.com | — | |
domainshadowrunevail.top | — | |
domainvoidravencitadel.com | — | |
domainvoidwalkerforge.top | — | |
domainwarmcoffeetime.top | — |
Threat ID: 6a959c28acd9273b4941a57f
Added to database: 08/31/2026, 15:22:16 UTC
Last updated: 08/31/2026, 23:56:38 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.