Advisory
Published 2026-08-28
Verified 2026-09-19

HexMage Magecart: EtherHiding on Ethereum Sepolia to skim e-commerce checkouts

Confiant (28 August 2026; figures as of 25 August) tracks HexMage, a Magecart cluster that injects a fake Google Tag Manager block into compromised storefronts (mostly WooCommerce), loads ethers.js, and reads a Sepolia testnet contract to obtain a disposable skimmer host (EtherHiding). Confiant observed 40+ impacted sites across at least 15 countries since about April 2026; 25 storefronts mapped, including Australian site protocoffee[.]com[.]au (a blockchain-free loader variant pointing at stylerightnoww[.]com). One owner wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee) had deployed 144 contracts by 21 July 2026. The skimmer overlays the payment form, harvests PAN/expiry/CVV, then restores the DOM so the purchase completes. Fake-GTM detection: the injected block never fetches googletagmanager[.]com/gtm.js. Cyber Security News carried the story on 31 August. Defanged names only on this desk โ€” not live links.

Product
WooCommerce / PrestaShop / Magento / WordPress checkouts (injected fake GTM)
Versions
n/a (server-side skimmer; not a product CVE)
Exploited in Australia?
unknown
Patch to
Hunt fake GTM snippets that never load gtm.js; ethers.js + JSON-RPC to 0xrpc[.]io/sep on checkout pages; rotate injected tags

Primary: Confiant (28 Aug 2026) ยท Vendor: Cyber Security News (31 Aug; secondary)

tech australia