• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

{{postValue.id}}

A new JavaScript payment card-skimmer is found by the security researchers that is named as Pipka. The malware was first found on a website of North American merchant in September 2019 by the Visa's Payment Fraud Disruption Group security researchers. And later the security researchers found the same malware in almost sixteen e-commerce sites.

The major motive of the malware is to evade detection by removing itself from the HTML code of a compromised website after it successfully executes.

After initial execution, the Pipka is not present within the HTML code and this is why it has a unique ability to evade its detection. The hackers were directly injecting Pipka into different locations on e-commerce sites. And this malware was especially targetting only the e-commerce sites. The hackers are using the Pipka malware to steal the payment card details of the users from the e-commerce sites.

The details consist of cardholder numbers, payment card account numbers, expiration dates, CVV numbers, and other several sensitive data.

The malware is capable of collecting billing data on one page and payment account data on another. A cipher ROT13 is used to encode and encrypt the base64 that is harvested data and later it is stored in a cookie for exfiltration. The researchers have advised the e-commerce website users to regularly scam and test their websites for vulnerabilities or malware and also to limit access to the administrative portal. It is also advisable to keep all your shopping carts and other online sites to keep upgraded.

Tags:
jacob
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Sebastian ?
How to change non required to required field in SuiteCRM Custom/Default Modules

How to change not required to the required field in SuiteCRM Custom/Default Modules?

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.