HexMage Magecart: EtherHiding on Ethereum Sepolia to skim e-commerce checkouts
Confiant (28 August 2026; figures as of 25 August) tracks HexMage, a Magecart cluster that injects a fake Google Tag Manager block into compromised storefronts (mostly WooCommerce), loads ethers.js, and reads a Sepolia testnet contract to obtain a disposable skimmer host (EtherHiding). Confiant observed 40+ impacted sites across at least 15 countries since about April 2026; 25 storefronts mapped, including Australian site protocoffee[.]com[.]au (a blockchain-free loader variant pointing at stylerightnoww[.]com). One owner wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee) had deployed 144 contracts by 21 July 2026. The skimmer overlays the payment form, harvests PAN/expiry/CVV, then restores the DOM so the purchase completes. Fake-GTM detection: the injected block never fetches googletagmanager[.]com/gtm.js. Cyber Security News carried the story on 31 August. Defanged names only on this desk โ not live links.
- Product
- WooCommerce / PrestaShop / Magento / WordPress checkouts (injected fake GTM)
- Versions
- n/a (server-side skimmer; not a product CVE)
- Exploited in Australia?
- unknown
- Patch to
- Hunt fake GTM snippets that never load gtm.js; ethers.js + JSON-RPC to 0xrpc[.]io/sep on checkout pages; rotate injected tags
Primary: Confiant (28 Aug 2026) ยท Vendor: Cyber Security News (31 Aug; secondary)
