Blog

PrestaShop skimming activity accelerates

Turaco Labs
July 27, 2026
4 mins

Tags:

eCommerce

Based on the trends identified by ThreatView on the escalation in PrestaShop attacks, the past month has brought a sharp inflection in both skimmer detections and overall malware prevalence on compromised PrestaShop storefronts.

What’s changed in the last month

PrestaShop: skimmer detections more than doubled

Digital skimmers detected on PrestaShop increased by ~110% month-over-month. That rate of change is notable on its own, but it also reinforces a broader pattern: the attack is not only ongoing, it’s growing.

This jump indicates more than “background noise.” When skimmer activity more than doubles in a month, it typically suggests one (or more) of the following:

  • attackers are scaling distribution of an existing campaign
  • exploitation of a high-leverage weakness (often outdated modules, vulnerable themes, or exposed admin surfaces)
  • compromised supply chain elements that allow rapid propagation

Regardless of the mechanism, the result is the same: PrestaShop merchants are experiencing the steepest increase in active skimming risk right now.

Magento 1: activity continues to rise

Magento 1 skimmer detections increased by ~29% month-over-month.

That growth aligns with the persistent reality of Magento 1: legacy deployments remain attractive targets because they frequently run on older stacks with aging extensions, and are more likely to be under-maintained.

The bigger story: PrestaShop malware growth is compounding

Skimmer counts matter - but they’re only part of the picture. The most important macro indicator is the overall malware footprint on PrestaShop sites.

From October 2025 to July 2026, malware on PrestaShop storefronts grew roughly an 8× increase over that period.

Put simply, the issue is not slowing down.

In practical terms, this kind of compounding growth implies:

  • compromises are not being fully remediated (reinfection or persistent access)
  • attackers are adding multiple payloads, not just a single skimmer
  • the ecosystem is seeing repeatable, scalable compromise paths

What merchants should do now (priorities)

If you run PrestaShop - or support clients who do - the key is to treat this as an active, fast-moving campaign rather than an occasional risk.

  1. Check for signs of compromise first Inspect the active theme for injected scripts, look for obfuscated JavaScript such as atob(), and review installed modules for suspicious additions including mloader or simplefilemanager. These are among the clearest indicators that a store may already be compromised. PrestaShop Security Alert
  2. Contain access immediately If compromise is suspected, change back-office, database, FTP, and SSH credentials straight away. Then reduce admin exposure by removing unnecessary access, tightening permissions, and strengthening authentication controls. PrestaShop Security Alert
  3. Hunt for persistence, not just the visible skimmer Do not assume that deleting one malicious script solves the problem. Review for backdoors, altered files, rogue modules, unexpected PHP files, suspicious scheduled tasks, and any signs of additional payloads or data exfiltration. Recent PrestaShop malware has become more evasive and can avoid casual inspection. Turaco Labs Foregenix
  4. Patch aggressively (core + modules + theme) Most skimmer incidents tie back to outdated components. Prioritize updates for any payment, checkout, analytics, or “helper” modules.
  5. Strengthen checkout monitoring Put controls in place to detect unexpected third-party scripts, suspicious outbound requests, and checkout-page manipulation. That matters because some recent skimmers have been designed to appear only under certain conditions, making one-off manual checks easy to miss. Foregenix
  6. Reduce admin exposure Enforce strong access controls, restrict admin panels by IP where possible, and enable additional authentication controls.
  7. Prepare a response playbook If a skimmer is found, you need a repeatable process: isolate, preserve evidence, clean, rotate secrets, validate checkout, and re-monitor.

Outlook

The market signal is clear: attackers are currently concentrating effort where it scales - and right now that’s PrestaShop. With skimmer detections up ~110% in a month, the trajectory points to continued pressure on merchants unless proactive, defensive action is taken.

Read Other Blog Articles

Digital Skimmer Targeting Is Shifting: What the Last 3 Months Tell Us

Turaco Labs
June 17, 2026
3 mins
eCommerce
Malware
Web Security

Over the last three months, the digital skimmer landscape has changed noticeably. Based on the latest ThreatView charts, Magento 2 remains the most targeted platform, but the biggest movement is elsewhere: Shopify has risen sharply and now appears to be the second most targeted platform for digital skimmers.

PrestaShop Attacks Are Escalating - What We’re Seeing and What Merchants Should Do Now

Turaco Labs
June 3, 2026
4 mins
eCommerce
Cybersecurity
Malware

In February 2026, we detected 327 compromised PrestaShop websites running card-harvesting malware loaders or digital skimmer malware. By the beginning of June 2026, that number had risen to 1,068. This is an active, expanding campaign affecting a growing number of merchants.

PolyShell and Magento: what merchants should do now

Turaco Labs
25 March 2026
4 mins
eCommerce
Magento
Malware
Web Security

A practical guide for Magento and Adobe Commerce merchants dealing with PolyShell: what it is, how to detect compromise, how ThreatView helps, and what to do next.

Proudly, designed, developed and maintained by Tecbot.