• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

6144

A new JavaScript payment card-skimmer is found by the security researchers that is named as Pipka. The malware was first found on a website of North American merchant in September 2019 by the Visa's Payment Fraud Disruption Group security researchers. And later the security researchers found the same malware in almost sixteen e-commerce sites.

The major motive of the malware is to evade detection by removing itself from the HTML code of a compromised website after it successfully executes.

After initial execution, the Pipka is not present within the HTML code and this is why it has a unique ability to evade its detection. The hackers were directly injecting Pipka into different locations on e-commerce sites. And this malware was especially targetting only the e-commerce sites. The hackers are using the Pipka malware to steal the payment card details of the users from the e-commerce sites.

The details consist of cardholder numbers, payment card account numbers, expiration dates, CVV numbers, and other several sensitive data.

The malware is capable of collecting billing data on one page and payment account data on another. A cipher ROT13 is used to encode and encrypt the base64 that is harvested data and later it is stored in a cookie for exfiltration. The researchers have advised the e-commerce website users to regularly scam and test their websites for vulnerabilities or malware and also to limit access to the administrative portal. It is also advisable to keep all your shopping carts and other online sites to keep upgraded.

Tags:
jacob
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Forums in Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

Related Forums in Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

Scam (Ransomware)
jayden class=
Will ransome virus will affect linux server
May 16, 2017

Related News in Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

Related News in Pipka - A New Skimmer Targets the payment card details from E-commerce Websites

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
Tracking pixels could be the next phishing attack
Tracking pixels could be the next phishing attack
Apr 21, 2017
Another fake Netflix email turned out to be phishing scam
Another fake Netflix email turned out to be phishing scam
Nov 9, 2017
ECh0raix Ransomware Strain QNAP NAS devices
ECh0raix Ransomware Strain QNAP NAS devices
Jul 30, 2019
SingleFile Used as a Veil in New Phishing Attacks
SingleFile Used as a Veil in New Phishing Attacks
Apr 9, 2019
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
'The Nasty List' Instagram Phishing Scam Targets Instagram Credentials
Apr 19, 2019
NIST Develops Guidelines For Dealing With Ransomware Recovery
NIST Develops Guidelines For Dealing With Ransomware Recovery
Sep 8, 2017
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
‘NamPoHyu Virus’ ransomware target vulnerable Samba servers
Apr 20, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaiah ?
What is the use of SUID & SGID commands

How to set the special permissions to the files and folders using SUID and SGID commands...

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.