Malicious Code
-
Hi,
I’m creating this topic to make your support team aware of this issue and also to urge anyone who sees this to check their code snippets for malicious code.
Yesterday a customer sent us a picture of our order received page. This is our page that displays the order summary to the customer after the payment has been processed. On this page their was a form injected at the top of the page prompting the user to input their card details again to confirm their purchase.
I placed the website in maintenance mode and inspected the form. The form contains the customers billing information which is hidden. So if the customer was to submit the form all their billing information and their card details are sent to the URL in the form which is dic.ngo. I’ve reported this domain to their registrar.
I discovered that malicious code was present in multiple code snippets. Our website’s security is stringent and something like this would usually be flagged but this was not. I’m not accusing Code Snippets of begin responsible for this. I just want people to be aware of this. I would call this a sophisticated attack compared to most phishing attempts. They used the code snippet plugin to add the malicious code that injects the form so our website security was unaware.
Be careful out there people.
Conor
- You must be logged in to reply to this topic.