TGTGInsighttelegram intelligenceLIVE / telegram public index
← The Hacker News
The Hacker News avatar

TGINSIGHT POST

Post #8622

@thehackernews

The Hacker News

Views7,740Post view count
PostedMar 1803/18/2026, 12:49 PM
Post content

Post content

🛑 A Magecart skimmer hid its payload in a favicon’s EXIF metadata, never entering the codebase. A fake CDN script fetched the image, decoded a hidden URL, and executed it in the browser. No repo changes. No scan alerts. Payment data was exfiltrated at checkout. 🔗 Loader chain and why static tools missed it → https://thehackernews.com/2026/03/claude-code-security-and-magecart.html