Sneaky Credit Card Skimmer Disguised as Harmless Facebook Tracker

Researchers studying cybersecurity have found a credit card skimmer that hides, in an effort to avoid detection, behind a phony Meta Pixel tracking script.

According to Sucuri, the malware infiltrates websites using programs that let custom code, such the Magento admin panel’s “Miscellaneous Scripts” area or WordPress plugins like Simple Custom CSS and JS.

According to security researcher Matt Morrow, custom script editors are popular among bad actors because they support malicious third-party JavaScript and can easily pass for benign by using naming conventions that match well-known scripts like Google Analytics or libraries like JQuery.

Similar components can be found in both the phony and authentic Meta Pixel tracker scripts

