Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning

0
Medium
Published: 08/31/2026 (08/31/2026, 14:59:35 UTC)
Source: AlienVault OTX General

Description

A sophisticated card-skimming operation targets e-commerce platforms by combining client-side payment skimming with EtherHiding techniques, staging payloads inside Ethereum blockchain smart-contract storage. The attackers compromise legitimate online storefronts, primarily WooCommerce installations along with PrestaShop, Magento, and WordPress sites, injecting a loader disguised as Google Tag Manager code. Over 40 impacted websites across fifteen countries have been observed since April 2026. The infrastructure includes 144 Sepolia contracts controlled by a single owner wallet, with 20 distinct contracts and corresponding skimmer-hosting domains identified in traffic. The malicious code is hidden server-side to appear as ordinary analytics plumbing while stealing credit card information from unsuspecting online shoppers.

Technical Details

Author
AlienVault
Tlp
white
References
[]
Adversary
null
Pulse Id
6a9596d78e30aca83cac86db
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainstyleranked.com
domainstyleshort.com
domainstyleussles.com
domainstylehailens.com
domainstyleouresen.com
domainstylehersi.com
domainstyleember.com
domainstylestyk.com
domainstyleoutspin.com
domainstylegamingg.com
domainstylehelloman.com
domainstylegamagee.com
domainstyletropik.com
domainstyletimeset.com
domainstylerunningg.com
domainstylerightnoww.com
domainstyleteleport.com
domainstylekanions.com
domainstyleleftt.com
domainstyleconnectorr.com
domainstylehipp.com
domainstylecaving.com
domainstylejunglee.com
domainstylehotrod.com
domainstylewify.com
domainstyledupstep.com
domainstyleanimal.com
domainstreetfleshroyalgaming.top
domainstyleferry.com
domainstylebonus.com
domainstylerazorr.com
domainstyletumor.com
domainstylecholera.com
domainstyletray.com
domainstylepenalty.com
domainstylekay.com
domainstyleboosted.com
domainstyledespair.com
domainsmartpeoplework.info
domainblueoceanbreeze.org
domainsunnydaycoffees.net
domainnightstalkerwatch.top
domainravenstonekeep.top
domainashenravenfort.top
domainbloodboundcitadel.top
domainbloodthornkeep.top
domainbrokenvelvetdream.top
domaindarkflamewatch.top
domainfrozennebularhy.top
domainfrozenwildheart.top
domaingrimwardens.com
domainshadowrunevail.top
domainvoidravencitadel.com
domainvoidwalkerforge.top
domainwarmcoffeetime.top

Threat ID: 6a959c28acd9273b4941a57f

Added to database: 08/31/2026, 15:22:16 UTC

Last updated: 08/31/2026, 23:56:38 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses