216.73.216.6

Malware Steals Account Credentials

· Published 09/11/2024 01:13 · Modified 11/11/2024 09:55

Export JSON

Essential information

Published
09/11/2024 01:13
Modified
11/11/2024 09:55
Tags
2024-11-09 account hijacking admin access credential-theft e-commerce magento obfuscation
Related entities
6 techniques (mitre), 1 others

Description

A malicious script targeting sites, particularly , has been discovered. The script, found in the dataPost.js file, is heavily obfuscated and designed to steal customer account credentials and admin login details. It waits for login actions to trigger, then scrapes data entered into the form. The stolen information is sent to a domain mimicking legitimate jQuery repositories. This malware appears tailored for specific site designs, potentially allowing attackers to make site changes or install malicious modules. To protect against such attacks, regular password updates, software updates, principle of least privilege for admin accounts, and IP restrictions for admin logins are recommended.

External references