An Angrybeaver Has Joined The Skimming Game

angrybeaver is a skimmer written in JavaScript that is designed to target Payflowpro & authorizenet payments on Magento ecommerce websites. It doesn’t use the same obfuscation techniques that are popular among other JS skimmers.
Backticks + $_POST = PHP minishell

The use of the lesser known backtick operator and $_POST results in probably one of the smallest PHP one-liner minishells: ~12 characters
PaaS à la carte: Phishing Kit Caught In Development

A phishing kit found in-the-wild during the development stage and leaks the ‘order notes’ from the buyer.
.wtf() Skimmer Targets WooCommerce PayPal Pro

A JavaScript skimmer designed to steal payment data entered into the WooCommerce PayPal Pro gateway on the victim’s infected ecommerce website. Lowkey exfiltration domain: templatesurvey[.]com.
Skimmer Targets SagePay Payment Method on Magento 2 Websites

A skimmer that steals payment data from customers that check out using the SagePay payment method.