{"id":861,"date":"2026-06-09T11:04:00","date_gmt":"2026-06-09T05:34:00","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=861"},"modified":"2026-08-19T11:05:22","modified_gmt":"2026-08-19T05:35:22","slug":"magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/","title":{"rendered":"Magecart Skimmer Abuses Stripe API and Google Tag Manager to Steal Checkout Data"},"content":{"rendered":"<p>Magecart Stripe abuse shows how this payment-card theft campaign moved beyond traditional attacker-controlled infrastructure and into trusted cloud services that many organizations rely on every day.<\/p>\n<p>Researchers at Sansec uncovered a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-magecart\/\">Magecart<\/a> operation that abuses Google Tag Manager (GTM) and Stripe&#8217;s API infrastructure to deliver malicious code and collect stolen checkout information. Instead of relying on suspicious domains or obvious attacker-controlled infrastructure, the attackers use legitimate services that are commonly trusted by retailers and often permitted by default in web environments.<\/p>\n<p>The campaign targets Magento and Adobe Commerce checkout pages, where malicious code captures payment details and customer information during online transactions. The operation highlights a growing challenge for defenders: when attackers hide inside trusted services, domain reputation alone becomes a weak detection signal.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/xdr\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tDetect and contain threats with Hexnode XDR<\/a>\r\n    \t\t<\/center><\/p>\n<h2>Why attackers are moving into trusted SaaS platforms<\/h2>\n<p>The most notable aspect of this campaign is not the skimmer itself, but the infrastructure behind it. Instead of relying on attacker-controlled servers, the operators reportedly used trusted services such as Google Tag Manager and Stripe to deliver payloads and store stolen data.<\/p>\n<h3>This approach offers several advantages:<\/h3>\n<ul>\n<li>Traffic to trusted services is less likely to raise immediate suspicion.<\/li>\n<li>Many organizations already allow platforms such as Stripe and Google Tag Manager by default.<\/li>\n<li>Malicious activity can blend in with legitimate business operations.<\/li>\n<li>Domain reputation becomes a less effective detection signal.<\/li>\n<\/ul>\n<p>As organizations continue adopting cloud services and third-party integrations, defenders need to look beyond where traffic is going and pay closer attention to how trusted services are being used.<\/p>\n<h2>Anatomy of the Magecart Stripe abuse campaign<\/h2>\n<p>The campaign uses trusted cloud services at multiple stages of the attack chain, from payload delivery to data storage.<\/p>\n<h3>Stage 1: Loading the skimmer through GTM<\/h3>\n<p>The attack begins with a Google Tag Manager container that loads malicious code onto affected websites. The widespread use of Google Tag Manager can make malicious script activity more difficult to identify.<\/p>\n<h3>Stage 2: Retrieving code from Stripe metadata<\/h3>\n<p>The attackers reportedly stored JavaScript fragments within Stripe customer metadata fields. The browser retrieves and reconstructs the code through Stripe&#8217;s API before execution.<\/p>\n<h3>Stage 3: Capturing checkout information<\/h3>\n<p>Once active, the skimmer monitors checkout forms and collects payment card details along with customer information. The activity occurs within the browser, making detection more challenging.<\/p>\n<h3>Stage 4: Hiding stolen data inside Stripe records<\/h3>\n<p>The stolen information is reportedly obfuscated and stored in attacker-controlled Stripe customer metadata fields. This removes the need for a traditional attacker-operated exfiltration server.<\/p>\n<h3>Stage 5: Firestore-based variants<\/h3>\n<p>Researchers also identified a variant that uses Google Firestore for payload retrieval and data storage. The use of multiple cloud services suggests the operators are diversifying their infrastructure.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-analysis-.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Top 10 Cybersecurity Challenges for Enterprises<\/h4><p>Enterprise cybersecurity challenges and practical ways to reduce business risk.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/top-10-cybersecurity-challenges-for-enterprises\/\" aria-label=\"Top 10 Cybersecurity Challenges for Enterprises\"><\/a><\/div><\/div><\/div>\n<h2>Why traditional security controls struggle with this attack<\/h2>\n<p>This campaign highlights how trusted services can complicate detection efforts. Rather than relying on attacker-controlled infrastructure, the operators reportedly used platforms that many organizations already allow and depend on for business operations.<\/p>\n<h3>Key challenges include:<\/h3>\n<ul>\n<li>Trusted domains do not guarantee safe activity. The campaign used legitimate services such as Google Tag Manager and Stripe as part of the attack chain.<\/li>\n<li>Legitimate traffic can conceal malicious behavior. Activity involving trusted services can make it harder to distinguish malicious actions from normal business operations.<\/li>\n<li>Client-side threats create visibility gaps. Because web skimmers operate within the browser, suspicious activity may be more difficult to identify through traditional monitoring alone.<\/li>\n<\/ul>\n<h3>Operational summary table<\/h3>\n<table style=\"width: 68.7371%;\">\n<thead>\n<tr>\n<th style=\"width: 33.0986%; text-align: left;\">Component<\/th>\n<th style=\"width: 116.197%; text-align: left;\">Details<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 33.0986%;\">Threat Type<\/td>\n<td style=\"width: 116.197%;\">Magecart web-skimming campaign<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.0986%;\">Primary Technique<\/td>\n<td style=\"width: 116.197%;\">Trusted SaaS infrastructure abuse<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.0986%;\">Target Asset<\/td>\n<td style=\"width: 116.197%;\">E-commerce checkout pages<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.0986%;\">Affected Platforms<\/td>\n<td style=\"width: 116.197%;\">Magento and Adobe Commerce<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.0986%;\">Payload Sources<\/td>\n<td style=\"width: 116.197%;\">Stripe metadata and Google Firestore<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 33.0986%;\">Attacker Objective<\/td>\n<td style=\"width: 116.197%;\">Payment card and customer data theft<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>What this means for E-commerce security teams<\/h2>\n<p>The campaign demonstrates that modern web-skimming operations no longer require dedicated attacker infrastructure. Instead, attackers can abuse trusted services that many organizations already allow and depend on.<\/p>\n<h3>Trusted services can become part of the attack chain<\/h3>\n<p>The use of Google Tag Manager and Stripe highlights how legitimate platforms can be leveraged to support malicious activity. Security teams may need to evaluate not only which services are being used, but how they are being used.<\/p>\n<h3>Checkout integrity is just as important as website availability<\/h3>\n<p>Many organizations focus on keeping checkout systems online and performing reliably. This incident shows that monitoring the integrity of scripts running on checkout pages is equally important.<\/p>\n<h3>Small changes can have large consequences<\/h3>\n<p>Web-skimming attacks often require only minor modifications to existing website code. A single malicious script can affect every customer transaction until it is identified and removed.<\/p>\n<h3>Visibility must extend into the browser<\/h3>\n<p>Much of the activity in this campaign occurs within the customer&#8217;s browser rather than on the server. As client-side threats continue to evolve, organizations may need greater visibility into scripts, third-party integrations, and checkout-page behavior.<\/p>\n<h2>How to reduce exposure and mitigate risk<\/h2>\n<p>Organizations can reduce exposure by:<\/p>\n<ul>\n<li>Reviewing Google Tag Manager configurations and restricting publishing permissions.<\/li>\n<li>Implementing checkout-page integrity monitoring.<\/li>\n<li>Monitoring third-party scripts and dependencies for unauthorized changes.<\/li>\n<li>Applying strong access controls to e-commerce administration platforms.<\/li>\n<li>Reviewing payment processing and third-party service integrations regularly.<\/li>\n<li>Monitoring administrator devices and establishing response procedures for suspected compromises.<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to build stronger defenses and improve security operations today.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode supports threat investigation and response<\/h2>\n<p>Web-skimming campaigns often depend on access to administrative systems, website management platforms, or third-party integrations. Securing the devices used to manage these environments can help reduce risk and improve investigation readiness.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/\">Hexnode UEM<\/a> helps organizations enforce device compliance policies and gain visibility into non-compliant devices. <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> supports threat investigation by monitoring real-time endpoint events, detecting behavioral patterns, and correlating <a href=\"https:\/\/www.hexnode.com\/blogs\/xdr-extended-detection-and-response\/\">XDR<\/a> security alerts with UEM context.<\/p>\n<p>Together, these capabilities can help security teams improve visibility into the endpoints used to manage e-commerce platforms, payment integrations, and other business-critical web services.<\/p>\n<h2>Conclusion<\/h2>\n<p>The Magecart Stripe abuse campaign demonstrates how attackers can leverage trusted cloud services to support <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-web-skimmer\/\">web-skimming<\/a> operations. By using platforms commonly allowed in e-commerce environments, threat actors can make malicious activity more difficult to distinguish from legitimate business traffic.<\/p>\n<p>As organizations continue expanding their use of third-party services, monitoring checkout integrity, script behavior, and administrative systems becomes increasingly important. Strong governance, layered visibility, and effective investigation workflows remain essential for detecting and responding to modern web-skimming threats.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen visibility across critical systems <\/h5><p>See how Hexnode helps security teams investigate threats and improve endpoint security posture. <\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is Stripe compromised in this campaign?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Current reporting indicates attackers are abusing legitimate Stripe functionality rather than compromising Stripe itself. The reported activity involves attacker-controlled customer records and metadata fields.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Can traditional monitoring miss this type of attack?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Because the skimmer operates within the browser and uses trusted services, organizations may need checkout-page integrity monitoring and script visibility in addition to traditional security controls.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Why are Magento and Adobe Commerce frequently targeted?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Both platforms are widely used in e-commerce environments, making them attractive targets for financially motivated attackers seeking access to payment data.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Magecart Stripe abuse shows how this payment-card theft campaign moved beyond traditional attacker-controlled infrastructure and&#8230;<\/p>\n","protected":false},"author":5,"featured_media":864,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-861","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Magecart Stripe Abuse Targets E-Commerce Checkout Data<\/title>\n<meta name=\"description\" content=\"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Magecart Stripe Abuse Targets E-Commerce Checkout Data\" \/>\n<meta property=\"og:description\" content=\"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-09T05:34:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T05:35:22+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Magecart Skimmer Abuses Stripe API and Google Tag Manager to Steal Checkout Data\",\"datePublished\":\"2026-06-09T05:34:00+00:00\",\"dateModified\":\"2026-08-19T05:35:22+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/\"},\"wordCount\":1201,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/magecart-stripe-abuse.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/\",\"name\":\"Magecart Stripe Abuse Targets E-Commerce Checkout Data\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/magecart-stripe-abuse.jpeg?format=webp\",\"datePublished\":\"2026-06-09T05:34:00+00:00\",\"dateModified\":\"2026-08-19T05:35:22+00:00\",\"description\":\"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/magecart-stripe-abuse.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/magecart-stripe-abuse.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"magecart stripe abuse\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Magecart Skimmer Abuses Stripe API and Google Tag Manager to Steal Checkout Data\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Magecart Stripe Abuse Targets E-Commerce Checkout Data","description":"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/","og_locale":"en_US","og_type":"article","og_title":"Magecart Stripe Abuse Targets E-Commerce Checkout Data","og_description":"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-09T05:34:00+00:00","article_modified_time":"2026-08-19T05:35:22+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Magecart Skimmer Abuses Stripe API and Google Tag Manager to Steal Checkout Data","datePublished":"2026-06-09T05:34:00+00:00","dateModified":"2026-08-19T05:35:22+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/"},"wordCount":1201,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/","url":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/","name":"Magecart Stripe Abuse Targets E-Commerce Checkout Data","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp","datePublished":"2026-06-09T05:34:00+00:00","dateModified":"2026-08-19T05:35:22+00:00","description":"Magecart Stripe abuse campaign hides payment skimmers inside trusted cloud services to steal checkout data from online stores.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/magecart-stripe-abuse.jpeg?format=webp","width":1340,"height":700,"caption":"magecart stripe abuse"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/magecart-skimmer-abuses-stripe-api-and-google-tag-manager-to-steal-checkout-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Magecart Skimmer Abuses Stripe API and Google Tag Manager to Steal Checkout Data"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=861"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/861\/revisions"}],"predecessor-version":[{"id":866,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/861\/revisions\/866"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/864"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}