Attackers are exploiting Google Tag Manager by planting malicious code within e-commerce sites built on the Magento platform. The code can steal payment card data, demonstrating a new type of Magecart attack that leverages Google's free, legitimate website marketing tool. Researchers from Sucuri discovered an ongoing Magecart campaign in which attackers load code that appears to be a standard Google Tag Manager (GTM) and Google Analytics tracking script from a database onto e-commerce sites. These tracking scripts are typically used for website analytics and advertising purposes; however, the code used in the campaign has been tweaked to act as a card skimmer for the infected site, the researchers revealed in a recent blog post. "Within the GTM tag, there was an encoded JavaScript payload that acted as a credit card skimmer," Sucuri security analyst Puja Srivastava wrote in the post. "This script was designed to collect sensitive data entered by users during the checkout process and send it to a remote server controlled by the attackers." So far, Sucuri has uncovered at least six sites affected by the campaign, "indicating that this threat is actively affecting multiple sites," Srivastava wrote. The attack demonstrates a nontypical Magecart attack that leverages a legitimate free tool from Google that allows website owners to manage and deploy marketing tags on their website without needing to modify the site's code directly. GTM eliminates the need for developer intervention...
Magecart Attackers Abuse Google Ad Tool to Steal Data
Dark Reading
·Elizabeth Montalbano
·Published Feb 10, 2025
·Updated
Affected Software
4 affected components
Adobe Magento
Google Tag Manager
Google Tag Manager
Adobe Magento
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how Magecart attackers are exploiting Google Tag Manager to inject malicious code into e-commerce sites built on Magento.
2
What security implications are discussed?
The article highlights the risk of compromised payment card data due to vulnerabilities in the Google Tag Manager and Magento platforms.
3
What products or software are affected?
The affected products include Adobe Magento and Google Tag Manager.
4
How does the new Magecart attack method work?
The attackers plant malicious code through Google Tag Manager, which then steals sensitive payment information from users.
5
What should businesses do to protect against this type of attack?
Businesses are advised to review their use of Google Tag Manager and Magento, ensuring proper security measures are in place to counteract data theft.