WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

Researchers studying cybersecurity have found a new payment skimmer that circumvents security measures by using WebRTC data channels to receive payloads and exfiltrate data.

According to a research released this week by Sansec, this malware loads its payload and exfiltrates stolen payment data via WebRTC communication channels rather than the typical HTTP requests or image beacons.

PolyShell, a new vulnerability affecting Magento Open Source and Adobe Commerce that enables unauthenticated attackers to upload arbitrary executables via the REST API and accomplish code execution, is believed to have enabled the attack, which targeted an automaker’s online store.

Notably, beginning March 19, 2026, the vulnerability has been widely exploited, with over 50 IP addresses taking part in the scanning activities. According to the Dutch security firm, 56.7% of all exposed retailers had PolyShell attacks.

The skimmer is a self-executing script that creates a WebRTC peer connection read more about WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *