Magecart Group Uses Ethereum Smart Contracts for Global E-commerce Heists
The Magecart group has launched a new campaign, dubbed HexMage, which targets over 40 e-commerce stores across at least 15 countries. The attackers use Ethereum smart contracts as a delivery mechanism for payment-card skimmers.
The operation combines traditional client-side checkout theft with EtherHiding, allowing the attackers to conceal and rotate skimmer infrastructure through Ethereum's Sepolia testnet.
Researchers found that the malicious code is injected into the store itself, exposing every customer who reaches a compromised checkout. The campaign primarily targets WooCommerce sites, but also affects PrestaShop, Magento, and standard WordPress installations.