Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment information.


  • Attackers abuse Stripe API via Google Tag Manager
  • Malware scours payment data from compromised Magento sites
  • Stolen card details exfiltrated via api.stripe.com

Cybercriminals have turned Stripe into a malware hosting platform, in a new attack that steals online shoppers’ payment information. This is according to cybersecurity researcher Sansec, who discovered the campaign earlier this week.

Sansec claims that attackers managed to compromise some Magento/Adobe Commerce store websites and add a malicious Google Tag Manager (GTM) container.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top