CSIDB logo
Incident

Shopper Approved

Incident posture

Attack window
Sep 2018
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Shopper Approved
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A US-based provider of customer review widgets was compromised by Magecart attackers who injected malicious code into a legitimate JavaScript file used across client sites, enabling the theft of checkout form data transmitted to a remote server. The breach was detected early, limiting its duration and impact to a small fraction of checkout pages due to most clients not embedding the widget on payment pages and the skimmer's activation being conditional on specific URL keywords. Researchers identified the attack after hackers briefly exposed unobfuscated code, revealing infrastructure ties to a prior Magecart incident involving another widget provider. The company swiftly removed the malicious script and notified affected customers.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 15, 2018, cybersecurity firm RiskIQ detected a Magecart malware breach targeting Shopper Approved, a US-based provider of customer review widgets embedded on third-party e-commerce sites. Attackers compromised Shopper Approved's server infrastructure and inserted malicious code into the legitimate certificate.js file hosted at shopperapproved.com/seals/certificate.js. This file formed part of the company's rating widget distributed to client websites. The injected skimmer code collected payment card details and personal information entered into checkout forms, exfiltrating data to the attacker-controlled domain info-stat.ws. RiskIQ noted this infrastructure had previously been used in the mid-September Feedify compromise involving similar Magecart tactics. Unlike the prolonged Feedify infection, the Shopper Approved breach lasted only two days. The company removed the malicious code on September 17 after being alerted by RiskIQ.

The incident impacted a limited number of checkout pages despite Shopper Approved's widget being deployed across thousands of sites. RiskIQ attributed the constrained scope to two factors: most clients didn't load the widget on checkout pages, and the skimmer activated only when checkout URLs contained specific keywords. Shopper Approved notified affected e-commerce sites where the compromised code executed. Forensic analysis revealed attackers initially uploaded a clean, unobfuscated version of their skimmer code to the certificate.js file before replacing it with an obfuscated variant 15 minutes later. This oversight provided researchers with unmodified code samples to analyze the group's techniques. The breach exemplified Magecart's operational pattern of compromising third-party service providers to harvest payment data across multiple downstream victims. RiskIQ confirmed the attackers leveraged identical infrastructure across multiple campaigns, including the Feedify intrusion occurring contemporaneously.

Sources

Sources available to members: 1 source.

CSIDB