Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A Magecart-style skimmer was reported on Magento-based storefronts just before Black Friday 2024. Sucuri researcher Weston Henry found malicious JavaScript that could present a fake card form or read information entered into legitimate checkout fields, then send collected data to attacker-controlled infrastructure. The report, published November 27, 2024, did not identify a Magento vulnerability, affected-version range, victim count, or responsible group. This is a historical incident—not evidence of a new August 2026 campaign.
What happened
Dark Reading reported that Sucuri’s Weston Henry identified the skimmer during a site inspection using Sucuri SiteCheck. The suspicious resource was observed loading from dynamicopenfonts[.]app, a domain with a name resembling a font service. The report said malicious code had been placed in a Magento layout XML file using a <referenceContainer> directive, as well as in another location that was not fully specified.
A layout change can cause an external JavaScript file to load on storefront pages. The report describes the injection point and behavior, but not how the attackers first gained access. It does not establish whether they exploited a platform or extension flaw, stole credentials, compromised a development or supply-chain process, or used another route.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The timing made the discovery consequential: Black Friday in 2024 fell on November 29, two days after the report. Higher checkout volume can mean more opportunities to collect payment data, while merchants may be reluctant to disrupt sales. The reporting does not prove that attackers chose the campaign timing specifically because of Black Friday.
#1 Best Overall
- STYLISHLY SMALL, SLIM & DISCREET: Measuring just 3 1/8" x 4 7/16", our RFID front pocket wallet is designed to be super thin and exceptionally slim. Its modern, minimalist profile fits perfectly in your pocket, purse, or travel pack without adding bulk.
- SURPRISINGLY SPACIOUS: Though slim, it features 8 slots to easily organize your essentials. Comfortably holds your driver's license, credit cards, debit cards, and membership cards, keeping everything you need right at your fingertips.
- ADVANCED RFID BLOCKING: Our slim wallets for men and women are outfitted with advanced RFID SECURE Technology. They block electronic signals to keep your identity protected while you travel, shop, or explore, safeguarding you from digital theft.
- DURABLE & STYLISH FAUX LEATHER: Crafted from premium synthetic leather, this minimalist wallet sleeve combines a luxurious look and feel with everyday functionality. Its durable construction is designed to withstand the rigors of daily use, travel, and shopping.
- THE PERFECT UNISEX GIFT: With its sleek design and practical security features, this wallet is a popular choice for both men and women. It arrives ready for gifting, making it an ideal present for the frequent traveler, minimalist, or anyone in your life!
How the skimmer reportedly worked
The script checked the page URL for checkout and excluded URLs containing cart, narrowing its activity to checkout-like pages rather than the shopping cart. One reported method displayed a fraudulent card-entry form. Another read information from legitimate payment fields and Magento customer or quote data.
Reported or potentially collected information included payment-card details, customer name, billing address, email address, phone number, and other billing information. The report does not establish that every variant collected every listed field, or that full card numbers, CVVs, passwords, or authentication tokens were always captured.
Rank #2
- Slim and Thin Wallet - This minimalist bifold wallet measures 4.3x3.2x0.6 inches and stores up to 15 cards. The bifold wallet perfectly fits in your pocket and is well-suited for everyday carry
- Elite Features - 2 ID windows (DL & Other ID Cards) and 2 quick slots allow for quick access during travel, shopping or work. With 15 card slots and 2 more slots behind them, it is easy to carry all your important cards,cash and bills, meet all your daily needs
- RFID Blocking- Our wallets are equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorized scans.License and ID cards will be protected effectively. No more worrying about unauthorized scans during travel, shopping, or daily commuting!
- Durable Surface - Our leather wallets are pressed with high quality 3 layers leather, which is more durable than 2 layers leather wallets. The surface of the leather is made more scratch-resistant by special treatment, which can effectively prevent small scratches caused by keys and buttons in life
- Gifts for him - The thin wallet comes in classy gift packaging. It is a perfect present for birthdays, anniversaries, Father's Day, Valentine's Day, Christmas and other special occasions, so you can easily gift it to someone you love
Collected data was reportedly assembled as JSON, XOR-obfuscated with the key script, then Base64-encoded and sent using a browser beaconing mechanism. A second reported domain, staticfonts[.]com, was associated with the transmission. XOR and Base64 are not strong encryption: they can obscure data from casual inspection, but do not provide meaningful confidentiality against a capable investigator. These domains are historical indicators from the report, not proof that they remain malicious or active today.
Why it could be hard to spot
- It ran selectively. A script that activates on checkout pages may not show symptoms during ordinary browsing.
- It could leave the visible checkout intact. Reading legitimate fields may be less noticeable than replacing the entire payment flow.
- It loaded remotely. Names that resemble font or asset services can make an unfamiliar resource easier to overlook.
- It obscured collected data. Encoding and obfuscation can complicate casual review of scripts and network traffic.
- It may persist in more than one place. A layout file was reported, but the second location was not detailed. Removing one visible script does not prove that the store is clean.
The incident report does not publish a complete malware sample, hashes, exact selectors, or a forensic rule. Do not treat the two domains as a complete indicator set or assume that a basic external scan can rule out an infection.
Rank #3
- Ultra-thin: This wallet measures 4.3 x 3 x 0.5 inches and can hold at least 11 cards and 15-20 bills. Even when it's packed full, it's only 0.8 inches thick,It can perfectly conceal itself in your pocket without any noticeable bulge.
- Rfid Blocking: Our wallets are equipped with German Instiute Certified RFID Security technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals to protect the valuable information and privac.
- Lifetime After-sales Service: Regardless of the circumstances, if any GSOIAX brand wallet has a quality issue during your use, we promise to provide a full, unconditional, refund within 24 hours!
- Durable Surface: Crafted from premium 3-layer leather, our wallets outperform 2-layer alternatives in durability. Specially treated leather exterior delivers enhanced scratch resistance to guard against minor scuffs from everyday items like keys and buttons.
- Perfect Gifts For Him: This Money Clips Wallets for men comes in classy gift box package. It's a good idea to send the mens wallets as the gifts in birthday,anniversaries, Fathers Day,Valentine's Day,Christmas and other special occasions to someone you love.
What is confirmed—and what is not
The incident is reasonably described as Magecart-style: “Magecart” is commonly used as an umbrella label for online payment-card skimming techniques and campaigns. The report does not attribute this operation to a named Magecart group.
Nor does it identify a CVE, Magento or Adobe Commerce version range, confirmed vulnerable extension, exploit chain, number of affected stores, or initial-access method. The evidence supports reporting that malicious checkout JavaScript was found; it does not support saying Magento itself had a newly disclosed Black Friday flaw or that all Magento stores were affected.
Rank #4
- 【RFID Blocking Wallet for Men】Protect your personal information with our advanced RFID blocking tech. The wallet features a durable metal shell and composite materials that block 13.56 MHz and higher RFID signals, keeping your credit cards and IDs safe from electronic theft no matter where you are
- 【Card Slides Out Smoothly】This minimalist wallet features a button-activated ejection mechanism that pops cards up for easy access. The inner-facing slot ensures cards stay secure and never fall out
- 【Minimalist, Perfectly Slim】Designed to be sleek and easy to carry, featuring a dedicated ID card slot that allows for swiping without removing the card. It's perfect for ID cards, work badges, access cards, and transit cards. A separate cash compartment keeps your bills organized
- 【12 Card Slots & Cash Slot】Offers a total capacity of 12 cards (6 cards fitting in the chamber, 1 ID card, 4 slots on the wallet's outer surface, 1 slot on the card case exterior) and a cash slot. It features premium leather and aluminum chamber with a smooth pop-up card function, secured by a magnetic cover
- 【Premium Craftsmanship】Discover the perfect blend of quality and functionality with our wallet. Crafted from premium leather and airplane-grade aluminum, it features a convenient side pop-up for easy access. Durable and stylish, it complements both business and casual settings
That distinction matters. A platform vulnerability is only one possible route. An attacker could also gain access through an extension or theme, compromised administrator or infrastructure credentials, a vendor or deployment pipeline, or an earlier compromise that left persistence in files or database-backed settings. The available reporting does not resolve which route applied here.
If you operate a Magento store: response checklist
If you find a suspicious checkout script or have reason to believe payment data may still be exposed, treat it as an incident rather than a routine cleanup task.
Best Value
- ★REAL LEATHER: This wallet is MADE IN INDIA and comes in 2 leather qualities, namely Nappa and Crazy Horse. Nappa leather is conventional drum dyed leather which is finished with natural pigments to attain a smooth and buttery touch, while Crazy Horse is vegetable tanned and sprayed with oils and waxes to give a distressed look with warm and soft touch.
- ★ELITE FEATURES: ID windows allow for quick access when traveling or at the store /working place. With 5 card slots and 2 more slots behind them, it’s easy to carry all your important cards, meet all your daily needs.
- ★RFID BLOCKING ANTI THEFT SECURITY: Our wallets are anti theft, equipped with advanced RFID SECURE Technology, a unique metal composite, engineered specifically to block 13.56 MHz or higher RFID signals and protect the valuable information stored on RFID chips from unauthorised scans and make them anti theft.
- ★COMPACT DESIGN: Making this bifold superb for travel, and everyday use, keeping cards safe and organized! It holds 8+ cards, and lots of cash!
- ★GIFT BOX PACKING: It is one of the most special gifts for Groomsmen, Birthdays, Anniversaries, Father's Day, Christmas and other Special Occasions.
- Contain current exposure. If necessary, put checkout into controlled maintenance or use a known-safe payment path while you investigate. Remove or disable suspicious external scripts, and block known indicators at appropriate DNS, proxy, WAF, and monitoring layers. Blocking a domain alone is not a full fix.
- Preserve evidence first. Before deleting files or database content, preserve affected files, relevant database rows, web-server and CDN logs, deployment records, and controlled browser/network captures. Record timestamps and changes. This can help establish both the entry point and exposure window.
- Establish when and where it ran. Compare the first unauthorized change with the last known-clean deployment or backup. Determine which store views, domains, devices, cached pages, and checkout flows served the code. Review checkout activity during the possible exposure period and whether hosted payment fields or redirects were involved.
- Inspect beyond the obvious script. Depending on your deployment, review layout XML, theme templates, RequireJS configuration and JavaScript bundles, CMS blocks and pages, database-stored design or configuration settings, administrator users and roles, scheduled tasks, upload directories, web-server configuration, payment modules, CDN and tag-manager settings, repositories, and build artifacts. Exact paths differ among Magento Open Source, Adobe Commerce, Composer deployments, cloud environments, and custom implementations.
- Revoke access and rotate secrets. Remove unknown users and integrations. After you have a clean environment, rotate administrator, SSH/SFTP, hosting, database, CI/CD, cloud, and repository credentials; review payment-gateway API credentials and webhook secrets; invalidate sessions or tokens where supported; and enable multifactor authentication for administrator and infrastructure access.
- Restore from a trusted source. Patch to supported security releases, update extensions, and replace altered core or vendor files from trusted packages. Rebuild static content and deploy from a known-clean source tree. Review Composer dependencies and lockfiles, remove abandoned or unnecessary extensions, and compare production against trustworthy version-control or vendor baselines. Check related stores and environments, not only the first affected domain.
- Bring in the right responders. Notify your payment processor, acquiring bank, incident-response provider, and relevant legal or compliance teams. Assess whether cardholder or personal information entered during the exposure window was likely accessed. Preserve evidence for investigators, insurers, processors, and law enforcement as appropriate.
- Decide on customer communications from the facts. Notification duties depend on the merchant’s location, customer geography, contractual obligations, and what the investigation establishes. Use verified channels if customer outreach is warranted; do not make unsupported claims about who was affected or what data was taken.
How to check a suspected compromise
- Compare current layout, template, and JavaScript files with a known-clean deployment. Search for newly added remote script URLs and unfamiliar domains that imitate fonts, analytics, CDNs, or payment providers.
- In a controlled test environment, use browser developer tools and the Network panel to inspect checkout behavior and requests after test payment-field interaction. Test desktop and mobile flows without using real card details.
- Review Content Security Policy (CSP) violation reports, file-integrity alerts, malware scans, WAF and access logs, and records of administrative changes or unusual file writes.
- Confirm that checkout loads only approved scripts and communicates only with approved origins. Monitor changes to checkout templates, layout XML, CMS content, and database-backed configuration.
A scanner result is a useful signal, not proof that a store is clean or that historical data was never exposed. Conditional execution, geolocation or user-agent filters, caching, short-lived payloads, and database-stored code can all limit what an outside scan sees.
Prevention controls—and what they cannot do
Before a busy sales period, maintain supported platform and extension versions, remove components you do not need, require multifactor authentication, restrict access by role, and deploy changes from reviewed, version-controlled sources. Keep tested backups and an incident runbook that identifies who can pause checkout, preserve evidence, contact the processor, and approve emergency changes.
- WAF and CDN: Useful for filtering attack traffic, blocking known indicators, rate limiting, and protecting the origin. They do not necessarily detect malicious code already stored in a theme, layout, or database, or stop an authorized account from changing checkout files. Misconfiguration can also disrupt payment callbacks and APIs.
- File-integrity monitoring: Can alert on unauthorized changes and help build a timeline. It needs a trustworthy baseline, may miss database-stored injections, and does not prevent theft before an alert is acted on.
- External scanning: Can identify visible injections and known indicators, but may miss conditional, authenticated, or historical activity. A clean scan is not a forensic conclusion.
- CSP: A carefully tested policy can restrict which origins load scripts or receive connections and can surface violations. It needs an accurate inventory of legitimate integrations; a permissive policy offers little protection, and CSP cannot repair a compromised first-party script.
- Hosted fields or payment redirects: May reduce how much card data passes through a merchant-controlled page, but a compromised page can still steal customer information, manipulate or redirect checkout, or interfere with the payment flow. These approaches are not a complete defense against a compromised storefront.
When choosing a security provider, ask whether it inspects client-side scripts and checkout changes, detects database-stored content, retains historical logs, can restrict unexpected outbound connections, supports your Magento deployment and payment integrations, and includes cleanup or only alerts. No single tool covers initial access, persistence, skimming, credential theft, historical exposure, customer communications, and payment-response obligations equally well.
What shoppers can do
If you used a store later confirmed to have had a compromised checkout, monitor your card account, turn on transaction alerts, and contact the card issuer promptly about unfamiliar charges. Follow the issuer’s instructions for replacing a card or disputing transactions. Avoid entering payment details if checkout behaves unusually or redirects unexpectedly. A browser padlock indicates an encrypted connection; it does not prove that the merchant’s checkout or its scripts are trustworthy.
Quick Recap
Sources
- Dark Reading’s report on the Magento skimmer and Sucuri findings
- CERT.at’s November 28, 2024 daily security report, which listed the incident report
- Sucuri’s overview of website vulnerability scanning
- Sucuri’s malware threat-report context on compromised websites
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

