Hundreds of e-commerce sites hacked in supply-chain attack
arstechnica.comPublished: 5/5/2025
Summary
E-commerce sites were targeted by malware via backdoors in their browsers, allowing attackers to steal payment data and execute code on infected servers. Attackers exploited a six-year dormant supply-chain attack affecting three software suppliers, with at least 500 e-commerce sites already compromised. Adobe, which acquired Magento, is also potentially affected as it sources some software from Weltpixel, which may be infected. This attack poses a significant risk to millions of users due to its ability to execute arbitrary code and steal sensitive information.