Skimmer Targets Psigate Payment Fields

Analysis of an obfuscated JavaScript skimmer designed to steal payment data entered into the Psigate gateway fields on the victim’s infected ecommerce website. Exfiltration domain: …
MAGECART GROUP 12: toolser.pw skimmer

This PHP code injection is used to selectively inject the JavaScript skimmer that is loaded from
toolser.pw
(recently had been using pathc.space
).
wss://hotjar[.]info skimmer
![wss://hotjar[.]info skimmer](https://lukeleal.com/research/hotjar1.jpg)
A twist on the old ‘analytics code’ camouflage used by some skimmers to evade detection.
analiticsweb.site (zulhqmnr@netmail[.]tk) skimmer
![analiticsweb.site (zulhqmnr@netmail[.]tk) skimmer](https://lukeleal.com/research/zul.png)
A JavaScript skimmer that loads from analiticsweb[.]site/analytics.js - and opsec failure leads to discovery of more malicious domains.
lolzilla Skimmer: PHP or JS?

lolzilla skimmer analyzes a visitor’s HTTP request to determine whether it can capture the visitor’s payment data using a PHP skimmer or if it should deploy a JavaScript skimmer onto the checkout page to capture the data.