Tags:
A noteworthy and somewhat expected trend is emerging within the eCommerce cyber security world: a shift towards stealthier strategies to conceal eCommerce skimmers. These tactics include:

This trend towards more "stealthy malware" has been evolving over the past year, marking a logical progression from the more overt "Magecart-like" malware that plagued vulnerable websites in recent times.
While the numbers of hacked sites with card harvesting malware remains high, these stealthier methods afford criminals prolonged access ("dwell time") to websites, allowing for the extraction of a substantial amount of personally identifiable information (PII) and payment data from unsuspecting customers of the hacked websites.
To defend against these attacks, implementing basic security measures is crucial:
In the ongoing battle against cyber threats, proactive security measures are imperative. Our team has had an interesting year so far. Aside from the steady flow of eCommerce site investigations involving the standard Magecart-type skimmers, a "collection" of new types of malware have been identified, documented, "fingerprinted" and loaded into our technology to help defend our clients globally.
Recent additions to our malware fingerprint database over the past nine months include:
As criminal tactics evolve, staying ahead of the curve with robust security protocols can significantly safeguard your business from potential breaches and ensure sustained success.
In February 2026, we detected 327 compromised PrestaShop websites running card-harvesting malware loaders or digital skimmer malware. By the beginning of June 2026, that number had risen to 1,068. This is an active, expanding campaign affecting a growing number of merchants.
A practical guide for Magento and Adobe Commerce merchants dealing with PolyShell: what it is, how to detect compromise, how ThreatView helps, and what to do next.
At Turaco Labs, our ThreatView telemetry has detected a concerning spike in compromised PrestaShop websites. As of this morning, we have identified 327 hacked sites actively running payload loaders or digital skimmer malware.