Stripe API Skimming Campaign Unveils New Techniques for Theft
A new skimming attack leveraging the Stripe API to steal payment information has been uncovered by cybersecurity researchers at Jscrambler. The attack, which injects a malicious script into e-commerce checkout pages, operates by intercepting and exfiltrating customer payment details in real-time. Unlike traditional skimmers, which often insert rogue payment forms, this campaign exploits the legitimate Stripe API to siphon off data. According to a new advisory published by Jscrambler today, the attackers inject JavaScript directly…
Read More