Skip to main content
All Terms Glossary

Digital Skimmers

Definition

Digital skimmers are malicious scripts injected into websites to steal sensitive information, particularly payment card data. Similar to physical card skimmers, these scripts intercept data as users enter it into web forms. Magecart attacks are a notorious example of digital skimming. Prevention involves monitoring third-party scripts, implementing CSP, and regularly scanning for unauthorized code changes.

What a digital skimmer is

A digital skimmer is malicious JavaScript that copies data from web forms as a user fills them in, most often payment card numbers, security codes, and billing details on a checkout page. It is the client-side equivalent of the physical card skimmers criminals attach to ATMs and fuel pumps, except it never touches hardware and can be planted remotely by editing a script the site loads.

Where skimmers hide

Skimmers are usually added to third-party scripts, tag managers, A/B testing tools, live-chat widgets, or a compromised JavaScript library on a CDN, so they load on the page without any change to the merchant's own code. Advanced skimmers obfuscate themselves, only activate on pages with a payment form, and exfiltrate stolen data to look-alike domains that blend in with normal analytics traffic.

Detecting skimmers with cside

Because skimmers run in the browser and hide inside trusted scripts, they are invisible to server-side monitoring. cside inspects the behaviour of every third-party script and analyses its payload on our side, flagging code that reads sensitive form fields or sends data to an unexpected destination, and records the offending payload for forensic review. That gives security and compliance teams evidence of exactly what executed, rather than an alert with no context.

Definition

Are digital skimmers and Magecart the same thing?

They overlap. Magecart refers to the threat groups and campaigns; a digital skimmer is the actual malicious script they deploy. Formjacking is another name for the same technique. In practice teams use the terms interchangeably when describing browser-based payment theft.

Definition

Why don't antivirus or WAF tools catch skimmers?

Antivirus protects the endpoint's operating system, and a WAF inspects traffic to your server. A skimmer runs inside the visitor's browser session on a legitimate page, so neither tool sees it. Detection has to observe what scripts do on the client side.

Got more questions

Talk to a security expert

We answer client-side security questions every day. Bring yours.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead