Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Magento Checkout Skimmer Found Before Black Friday: What Merchants and Shoppers Need to Know

By TheFinanceBase Team8 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A Magecart-style skimmer was reported on Magento-based storefronts just before Black Friday 2024. Sucuri researcher Weston Henry found malicious JavaScript that could present a fake card form or read information entered into legitimate checkout fields, then send collected data to attacker-controlled infrastructure. The report, published November 27, 2024, did not identify a Magento vulnerability, affected-version range, victim count, or responsible group. This is a historical incident—not evidence of a new August 2026 campaign.

What happened

Dark Reading reported that Sucuri’s Weston Henry identified the skimmer during a site inspection using Sucuri SiteCheck. The suspicious resource was observed loading from dynamicopenfonts[.]app, a domain with a name resembling a font service. The report said malicious code had been placed in a Magento layout XML file using a <referenceContainer> directive, as well as in another location that was not fully specified.

A layout change can cause an external JavaScript file to load on storefront pages. The report describes the injection point and behavior, but not how the attackers first gained access. It does not establish whether they exploited a platform or extension flaw, stole credentials, compromised a development or supply-chain process, or used another route.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The timing made the discovery consequential: Black Friday in 2024 fell on November 29, two days after the report. Higher checkout volume can mean more opportunities to collect payment data, while merchants may be reluctant to disrupt sales. The reporting does not prove that attackers chose the campaign timing specifically because of Black Friday.

#1 Best Overall
Buffway Slim Minimalist Front Pocket RFID Blocking Leather Wallets for Men and Women - Carbon Fiber Black
  • STYLISHLY SMALL, SLIM & DISCREET: Measuring just 3 1/8" x 4 7/16", our RFID front pocket wallet is designed to be super thin and exceptionally slim. Its modern, minimalist profile fits perfectly in your pocket, purse, or travel pack without adding bulk.
  • SURPRISINGLY SPACIOUS: Though slim, it features 8 slots to easily organize your essentials. Comfortably holds your driver's license, credit cards, debit cards, and membership cards, keeping everything you need right at your fingertips.
  • ADVANCED RFID BLOCKING: Our slim wallets for men and women are outfitted with advanced RFID SECURE Technology. They block electronic signals to keep your identity protected while you travel, shop, or explore, safeguarding you from digital theft.
  • DURABLE & STYLISH FAUX LEATHER: Crafted from premium synthetic leather, this minimalist wallet sleeve combines a luxurious look and feel with everyday functionality. Its durable construction is designed to withstand the rigors of daily use, travel, and shopping.
  • THE PERFECT UNISEX GIFT: With its sleek design and practical security features, this wallet is a popular choice for both men and women. It arrives ready for gifting, making it an ideal present for the frequent traveler, minimalist, or anyone in your life!

How the skimmer reportedly worked

The script checked the page URL for checkout and excluded URLs containing cart, narrowing its activity to checkout-like pages rather than the shopping cart. One reported method displayed a fraudulent card-entry form. Another read information from legitimate payment fields and Magento customer or quote data.

Reported or potentially collected information included payment-card details, customer name, billing address, email address, phone number, and other billing information. The report does not establish that every variant collected every listed field, or that full card numbers, CVVs, passwords, or authentication tokens were always captured.

Rank #2
Sale
RUNBOX Wallet for Men Slim Leather Bifold RFID Blocking with 2 ID Windows
  • Slim and Thin Wallet - This minimalist bifold wallet measures 4.3x3.2x0.6 inches and stores up to 15 cards. The bifold wallet perfectly fits in your pocket and is well-suited for everyday carry
  • Elite Features - 2 ID windows (DL & Other ID Cards) and 2 quick slots allow for quick access during travel, shopping or work. With 15 card slots and 2 more slots behind them, it is easy to carry all your important cards,cash and bills, meet all your daily needs
  • RFID Blocking- Our wallets are equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorized scans.License and ID cards will be protected effectively. No more worrying about unauthorized scans during travel, shopping, or daily commuting!
  • Durable Surface - Our leather wallets are pressed with high quality 3 layers leather, which is more durable than 2 layers leather wallets. The surface of the leather is made more scratch-resistant by special treatment, which can effectively prevent small scratches caused by keys and buttons in life
  • Gifts for him - The thin wallet comes in classy gift packaging. It is a perfect present for birthdays, anniversaries, Father's Day, Valentine's Day, Christmas and other special occasions, so you can easily gift it to someone you love

Collected data was reportedly assembled as JSON, XOR-obfuscated with the key script, then Base64-encoded and sent using a browser beaconing mechanism. A second reported domain, staticfonts[.]com, was associated with the transmission. XOR and Base64 are not strong encryption: they can obscure data from casual inspection, but do not provide meaningful confidentiality against a capable investigator. These domains are historical indicators from the report, not proof that they remain malicious or active today.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why it could be hard to spot

  • It ran selectively. A script that activates on checkout pages may not show symptoms during ordinary browsing.
  • It could leave the visible checkout intact. Reading legitimate fields may be less noticeable than replacing the entire payment flow.
  • It loaded remotely. Names that resemble font or asset services can make an unfamiliar resource easier to overlook.
  • It obscured collected data. Encoding and obfuscation can complicate casual review of scripts and network traffic.
  • It may persist in more than one place. A layout file was reported, but the second location was not detailed. Removing one visible script does not prove that the store is clean.

The incident report does not publish a complete malware sample, hashes, exact selectors, or a forensic rule. Do not treat the two domains as a complete indicator set or assume that a basic external scan can rule out an infection.

Rank #3
Sale
GSOIAX Slim Wallet for Men Rfid Blocking Leather Bifold Front Pocket Carbon Fiber Men's Money Clips Credit Card Holder With Gift Box
  • Ultra-thin: This wallet measures 4.3 x 3 x 0.5 inches and can hold at least 11 cards and 15-20 bills. Even when it's packed full, it's only 0.8 inches thick,It can perfectly conceal itself in your pocket without any noticeable bulge.
  • Rfid Blocking: Our wallets are equipped with German Instiute Certified RFID Security technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals to protect the valuable information and privac.
  • Lifetime After-sales Service: Regardless of the circumstances, if any GSOIAX brand wallet has a quality issue during your use, we promise to provide a full, unconditional, refund within 24 hours!
  • Durable Surface: Crafted from premium 3-layer leather, our wallets outperform 2-layer alternatives in durability. Specially treated leather exterior delivers enhanced scratch resistance to guard against minor scuffs from everyday items like keys and buttons.
  • Perfect Gifts For Him: This Money Clips Wallets for men comes in classy gift box package. It's a good idea to send the mens wallets as the gifts in birthday,anniversaries, Fathers Day,Valentine's Day,Christmas and other special occasions to someone you love.

What is confirmed—and what is not

The incident is reasonably described as Magecart-style: “Magecart” is commonly used as an umbrella label for online payment-card skimming techniques and campaigns. The report does not attribute this operation to a named Magecart group.

Nor does it identify a CVE, Magento or Adobe Commerce version range, confirmed vulnerable extension, exploit chain, number of affected stores, or initial-access method. The evidence supports reporting that malicious checkout JavaScript was found; it does not support saying Magento itself had a newly disclosed Black Friday flaw or that all Magento stores were affected.

Rank #4
2026 Wallet for Men - RFID Blocking Slim Minimalist Wallet, Carbon Fiber
  • 【RFID Blocking Wallet for Men】Protect your personal information with our advanced RFID blocking tech. The wallet features a durable metal shell and composite materials that block 13.56 MHz and higher RFID signals, keeping your credit cards and IDs safe from electronic theft no matter where you are
  • 【Card Slides Out Smoothly】This minimalist wallet features a button-activated ejection mechanism that pops cards up for easy access. The inner-facing slot ensures cards stay secure and never fall out
  • 【Minimalist, Perfectly Slim】Designed to be sleek and easy to carry, featuring a dedicated ID card slot that allows for swiping without removing the card. It's perfect for ID cards, work badges, access cards, and transit cards. A separate cash compartment keeps your bills organized
  • 【12 Card Slots & Cash Slot】Offers a total capacity of 12 cards (6 cards fitting in the chamber, 1 ID card, 4 slots on the wallet's outer surface, 1 slot on the card case exterior) and a cash slot. It features premium leather and aluminum chamber with a smooth pop-up card function, secured by a magnetic cover
  • 【Premium Craftsmanship】Discover the perfect blend of quality and functionality with our wallet. Crafted from premium leather and airplane-grade aluminum, it features a convenient side pop-up for easy access. Durable and stylish, it complements both business and casual settings

That distinction matters. A platform vulnerability is only one possible route. An attacker could also gain access through an extension or theme, compromised administrator or infrastructure credentials, a vendor or deployment pipeline, or an earlier compromise that left persistence in files or database-backed settings. The available reporting does not resolve which route applied here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you operate a Magento store: response checklist

If you find a suspicious checkout script or have reason to believe payment data may still be exposed, treat it as an incident rather than a routine cleanup task.

Best Value
Sale
Real Leather Mens Bifold Wallet RFID Blocking Slim Minimalist Front Pocket - Thin & Stylish with ID Window in Gift Box (Crazy Horse, Coffee)
  • ★REAL LEATHER: This wallet is MADE IN INDIA and comes in 2 leather qualities, namely Nappa and Crazy Horse. Nappa leather is conventional drum dyed leather which is finished with natural pigments to attain a smooth and buttery touch, while Crazy Horse is vegetable tanned and sprayed with oils and waxes to give a distressed look with warm and soft touch. 
  • ★ELITE FEATURES: ID windows allow for quick access when traveling or at the store /working place. With 5 card slots and 2 more slots behind them, it’s easy to carry all your important cards, meet all your daily needs.
  • ★RFID BLOCKING ANTI THEFT SECURITY: Our wallets are anti theft, equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorised scans and make them anti theft.
  • ★COMPACT DESIGN: Making this bifold superb for travel, and everyday use, keeping cards safe and organized! It holds 8+ cards, and lots of cash!
  • ★GIFT BOX PACKING: It is one of the most special gifts for Groomsmen, Birthdays, Anniversaries, Father's Day, Christmas and other Special Occasions.
  1. Contain current exposure. If necessary, put checkout into controlled maintenance or use a known-safe payment path while you investigate. Remove or disable suspicious external scripts, and block known indicators at appropriate DNS, proxy, WAF, and monitoring layers. Blocking a domain alone is not a full fix.
  2. Preserve evidence first. Before deleting files or database content, preserve affected files, relevant database rows, web-server and CDN logs, deployment records, and controlled browser/network captures. Record timestamps and changes. This can help establish both the entry point and exposure window.
  3. Establish when and where it ran. Compare the first unauthorized change with the last known-clean deployment or backup. Determine which store views, domains, devices, cached pages, and checkout flows served the code. Review checkout activity during the possible exposure period and whether hosted payment fields or redirects were involved.
  4. Inspect beyond the obvious script. Depending on your deployment, review layout XML, theme templates, RequireJS configuration and JavaScript bundles, CMS blocks and pages, database-stored design or configuration settings, administrator users and roles, scheduled tasks, upload directories, web-server configuration, payment modules, CDN and tag-manager settings, repositories, and build artifacts. Exact paths differ among Magento Open Source, Adobe Commerce, Composer deployments, cloud environments, and custom implementations.
  5. Revoke access and rotate secrets. Remove unknown users and integrations. After you have a clean environment, rotate administrator, SSH/SFTP, hosting, database, CI/CD, cloud, and repository credentials; review payment-gateway API credentials and webhook secrets; invalidate sessions or tokens where supported; and enable multifactor authentication for administrator and infrastructure access.
  6. Restore from a trusted source. Patch to supported security releases, update extensions, and replace altered core or vendor files from trusted packages. Rebuild static content and deploy from a known-clean source tree. Review Composer dependencies and lockfiles, remove abandoned or unnecessary extensions, and compare production against trustworthy version-control or vendor baselines. Check related stores and environments, not only the first affected domain.
  7. Bring in the right responders. Notify your payment processor, acquiring bank, incident-response provider, and relevant legal or compliance teams. Assess whether cardholder or personal information entered during the exposure window was likely accessed. Preserve evidence for investigators, insurers, processors, and law enforcement as appropriate.
  8. Decide on customer communications from the facts. Notification duties depend on the merchant’s location, customer geography, contractual obligations, and what the investigation establishes. Use verified channels if customer outreach is warranted; do not make unsupported claims about who was affected or what data was taken.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check a suspected compromise

  • Compare current layout, template, and JavaScript files with a known-clean deployment. Search for newly added remote script URLs and unfamiliar domains that imitate fonts, analytics, CDNs, or payment providers.
  • In a controlled test environment, use browser developer tools and the Network panel to inspect checkout behavior and requests after test payment-field interaction. Test desktop and mobile flows without using real card details.
  • Review Content Security Policy (CSP) violation reports, file-integrity alerts, malware scans, WAF and access logs, and records of administrative changes or unusual file writes.
  • Confirm that checkout loads only approved scripts and communicates only with approved origins. Monitor changes to checkout templates, layout XML, CMS content, and database-backed configuration.

A scanner result is a useful signal, not proof that a store is clean or that historical data was never exposed. Conditional execution, geolocation or user-agent filters, caching, short-lived payloads, and database-stored code can all limit what an outside scan sees.

Prevention controls—and what they cannot do

Before a busy sales period, maintain supported platform and extension versions, remove components you do not need, require multifactor authentication, restrict access by role, and deploy changes from reviewed, version-controlled sources. Keep tested backups and an incident runbook that identifies who can pause checkout, preserve evidence, contact the processor, and approve emergency changes.

  • WAF and CDN: Useful for filtering attack traffic, blocking known indicators, rate limiting, and protecting the origin. They do not necessarily detect malicious code already stored in a theme, layout, or database, or stop an authorized account from changing checkout files. Misconfiguration can also disrupt payment callbacks and APIs.
  • File-integrity monitoring: Can alert on unauthorized changes and help build a timeline. It needs a trustworthy baseline, may miss database-stored injections, and does not prevent theft before an alert is acted on.
  • External scanning: Can identify visible injections and known indicators, but may miss conditional, authenticated, or historical activity. A clean scan is not a forensic conclusion.
  • CSP: A carefully tested policy can restrict which origins load scripts or receive connections and can surface violations. It needs an accurate inventory of legitimate integrations; a permissive policy offers little protection, and CSP cannot repair a compromised first-party script.
  • Hosted fields or payment redirects: May reduce how much card data passes through a merchant-controlled page, but a compromised page can still steal customer information, manipulate or redirect checkout, or interfere with the payment flow. These approaches are not a complete defense against a compromised storefront.

When choosing a security provider, ask whether it inspects client-side scripts and checkout changes, detects database-stored content, retains historical logs, can restrict unexpected outbound connections, supports your Magento deployment and payment integrations, and includes cleanup or only alerts. No single tool covers initial access, persistence, skimming, credential theft, historical exposure, customer communications, and payment-response obligations equally well.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What shoppers can do

If you used a store later confirmed to have had a compromised checkout, monitor your card account, turn on transaction alerts, and contact the card issuer promptly about unfamiliar charges. Follow the issuer’s instructions for replacing a card or disputing transactions. Avoid entering payment details if checkout behaves unusually or redirects unexpectedly. A browser padlock indicates an encrypted connection; it does not prove that the merchant’s checkout or its scripts are trustworthy.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.