Technology

Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment details

2026-06-05 17:15
986 views
Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment details

Google Tag Manager is also abused in this campaign.

  1. Pro
  2. Security
Hackers abused Stripe and Google Tag Manager to launch a credit card theft campaign and host stolen payment details News By Sead Fadilpašić published 5 June 2026

Someone found a way to turn Stripe into a malware hosting platform

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Hands holding a credit card and mobile phone (Image credit: Getty Images)
  • Copy link
  • Facebook
  • X
  • Whatsapp
  • Reddit
  • Pinterest
  • Flipboard
  • Threads
  • Email
Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter
  • Attackers abuse Stripe API via Google Tag Manager
  • Malware skims checkout data from compromised Magento sites
  • Stolen card details exfiltrated through api.stripe.com

Cybercriminals have turned Stripe into a malware hosting platform, in a new attack that steals people’s payment information from online shoppers. This is according to cybersecurity researchers Sansec, who discovered the campaign earlier this week.

Sansec says that the attackers managed to compromise certain Magento/Adobe Commerce store websites, and add a malicious Google Tag Manager (GTM) container.

However, when a shopper visits the website, the browser loads the GTM container from Google’s servers, and when they reach checkout, the GTM code makes a request to Stripe’s API.

Latest Videos FromWatch full video here:

Stealing the information

GTM is a free tool that lets website owners manage tracking, analytics, and other scripts on a website without directly modifying the site's code. Since GTM is a widely used tool, loading code from googletagmanager.com looks completely normal and raises no red flags.

Since Stripe is an online payment processing platform that enables businesses to process financial transactions over the internet, there is still no foul play. But GTM actually retrieves a Stripe customer record controlled by the attackers, inside which are pieces of malicious JavaScript. The website downloads those pieces, reassembles them into a working script, then runs them in the browser, turning Stripe into a storage locker for malware code.

You may like
  • Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air. Now that's different - hackers use miniature SVG images to try and hide credit card stealer
  • Wordpress brand logo on computer screen. Man typing on the keyboard. Funnel Builder WordPress plugin exploited to steal credit card details
  • Business man using mobile phone and laptop with global network and technology icons on virtual screen Huge numbers of web stores are facing attack from this dangerous new malware

Once that script is running, it starts “watching” the checkout page, so when the victim types in their card details, the script copies everything, including the card number, CVV, name, address, and other relevant details.

Then, instead of sending the data to the attackers immediately, the malware first combines all stolen information into one string, applies XOR obfuscation, and stores the result locally in the browser. Then the malware creates a fake Stripe customer, splits the stolen data into two chunks, creates a new Stripe customer object in the attacker’s stripe account, and uploads the stolen information.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

"Both the payload and the stolen cards move through api.stripe.com. Stores allow that domain by default, so the skimmer slips past Content Security Policy rules and network filters that would otherwise flag traffic to an unknown skimmer domain," Sansec explained.

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.

CATEGORIES Cyber Security Computing Security Computing Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

View More

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more Someone typing at a keyboard, with an ecommerce shopping cart symbol floating in the air. Security Now that's different - hackers use miniature SVG images to try and hide credit card stealer    Wordpress brand logo on computer screen. Man typing on the keyboard. Security Funnel Builder WordPress plugin exploited to steal credit card details    Business man using mobile phone and laptop with global network and technology icons on virtual screen Security Huge numbers of web stores are facing attack from this dangerous new malware    Phishing Security Hackers hijack Google Ads to spread phishing campaign spoofing top GoDaddy tool    Logo of Steam with game covers in the background Security Steam Community Profiles abused as C2 network in new WordPress malware infection campaign    Based Apparel Security Kash Patel's 'BasedApparel' website is apparently hosting ClickFix malware    Latest in Security russian flag Security Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War    A detailed view of the FIFA World Cup Trophy during the VIP Welcome Reception ahead of the FIFA World Cup 2026 Official Draw at John F. Kennedy Center for the Performing Arts on December 04, 2025 Security FIFA World Cup 2026 hype kicks off fraud, fake apps, and ransomware targeting fans and businesses    A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background. Security ‘Data can place the lives of frontline military or other personnel at risk’: FBI warns that China is luring Western military and intelligence operatives with 'gig-work' job offers to steal secrets    A robot hand touching a locked digital shield blocking a human from accessing data Security Hackers could use poisoned WhatsApp and Slack notifications to take over your Google Gemini – and make it work on their behalf    Red padlock open on electric circuits network dark red background Security OpenAI’s Codex helps discover HTTP/2 Bomb DoS attack that can nuke over 30GB of RAM within seconds, knocking web servers offline before they can react    Industrial interior of water pump, valves, pressure gauges, motors inside engine room. Valve and pumps in an industrial room. Urban modern powerful pipelines and pumps, automatic control systems Security NSA warns that cybercriminals are targeting this one critical component that the energy, chemical, food, agriculture, and transportation sectors rely on - here's what we know    Latest in News The key artwork for Future Publishing's PC Gaming Show 2026 Gaming This year's PC Gaming Show will provide looks at more than 50 games and also feature a behind-the-scenes look at one of my most anticipated games of the year — here's how to tune in    Russia flag on the left, VPN icon on smarthpne on the right VPN Privacy & Security Russian Roskomnadzor accused of launching active DDoS attacks on VPN services — here's what we know so far    Joker at the School Festival Gaming One of my all-time favourite JRPGs has been announced for the Xbox Game Pass lineup for June ahead of the Xbox Games Showcase    Nintendo Switch 2 console with Mario Kart World playing on the screen Gaming 'Nintendo products are fully compliant with these requirements' — A new Nintendo Switch 2 model featuring a removable battery will be released in the EU soon to meet regulations    A masculine hand holding up an Nvidia GeForce RTX 5080 against a green background GPU Nvidia RTX 5000 Super GPU refreshes could arrive in 2026 after all    russian flag Security Russian hackers attack Europe for the Motherland in crypto fueled Great Patriotic Cyber War    LATEST ARTICLES