Skip to main content
Blog
Blog Attacks

Carlsberg a target in Magento "CosmicSting" malware attack

The term "Magecart" refers to attacks on the Magento platform. Recently, another large campaign was found to target Magento sites again. Among these, Carlsberg was one of the compromised websites. The pattern of these attacks is almost always the same. A single line of JavaScript loads content from a remote website. In other words, a 3rd party script. That code is then heavily obfuscated to delay detection even more. In this case, the payment process was quietly changed. A fake payment method

Oct 04, 2024 4 min read
carlsberg-a-target-image-cover

TL;DR: artvislon shop CosmicSting Magento skimmer

  • Name the victims: Named victims teach the industry. Anonymized breach reports let the next Carlsberg run the same unpatched Magento build for another quarter, because nobody at the board table felt personally exposed.
  • One line, fake payment box: One line of JavaScript pulled from artvislon[.]shop rendered a fake payment box before checkout, and threat feeds missed a sibling campaign for over two years. cside's browser-layer agent inspects every third-party script's runtime behavior before it can steal card data.
  • Patch Magento today: If your ecommerce runs Magento 2.4 or older, patch CosmicSting today. If you inherited a stack you cannot fully patch, put runtime script inspection in front of it before the next crawler-evading skimmer lands.

Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.

The term "Magecart" refers to attacks on the Magento platform. Recently, another large campaign was found to target Magento sites again. Among these, Carlsberg was one of the compromised websites.

The pattern of these attacks is almost always the same. A single line of JavaScript loads content from a remote website. In other words, a 3rd party script. That code is then heavily obfuscated to delay detection even more.

In this case, the payment process was quietly changed. A fake payment method box was added to the store's page and shown to customers first. As you'd type in your credit card details, that information is sent directly to the attacker.

This attack was dubbed the "CosmicSting" attack, and was reported months ago. A very detailed and recent writeup by Sansec can help you catch up.

URLScan has archived the code that was injected:

URLScan archive of the skimmer code injected into the compromised Magento store
Further detail of the malicious code archived by URLScan

The **https://artvislon[.]shop/img/**domain was used to inject the following:

Malicious code injected from the artvislon[.]shop domain

From there, Malwarebytes has reported more on the code itself if you wish to see it. It has since been removed from the impacted websites.

It's interesting - and a bit frustrating - that impacted companies often aren't called out by name in reports like these. While there's usually good intent behind keeping their identities hidden, it makes you wonder if this silence might be part of the problem.

If more companies were publicly named when client-side attacks like CosmicSting happen, it could raise much-needed awareness about the risks of 3rd party scripts and skimming malware and prevent other brands from facing similar attacks.

Keeping these breaches under wraps mutes the message to other companies and the public. When large, recognizable brands fall victim, it should serve as a wake-up call for other businesses to prioritize their client-side security.

These companies are often better resourced and have an experienced and dedicated security team. Companies of all sizes face issues with client-side security and do not have an eye on the problem until it goes wrong visibly and globally.

As we have seen with the Polyfill attack, depending on the user agent, time of day and IP a bad actor can inject a malicious script. Waiting for a security crawler to notice the attack on your behalf will only catch non-advanced, non-targeted attacks.

Without that spotlight on who is affected, others in the industry may not fully grasp the urgency and severity of these attacks.

That might prompt quicker adoption of better security practices and stronger defenses across the board.

While various concepts have been tried to combat these types of attacks, none have really worked. Threat feeds are reactionary, and often completely miss the mark. We just reported on this case where threat feeds missed an attack for over 2 years.

Malwarebytes detected the attack due to a few of their customers using their detection browser plugin. It successfully stopped the attack for those few specific customers which makes it a great solution for people aware of the dangers, but not those outside of that space.

As attacks keep happening, and since these client-side attacks are especially hard to spot, We built cside to change this. The website owner installs our script to load first to let cside monitor, secure and even optimize all other scripts on their sites.You can get started to protect your website and visitors for free.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead