Aspidochelone: The Beast That Waits
The Aspidochelone looks like solid ground until sailors dock and drown. A trusted third-party script works the same way: safe until it skims your customers' card data.
You've captured the Aspidochelone, the final creature of the hunt. Scroll down to claim your reward.
Sailors mistook the Aspidochelone's shell for an island, moored to it, and were dragged under. A trusted script on your checkout is the same false ground: it loads without suspicion, then skims card numbers and hijacks forms through Magecart and formjacking.
How to prevent the Aspidochelone's attack
Magecart is client-side skimming: attackers inject or compromise a script on your site, often a trusted third party, and it copies what customers type into payment and login forms, then sends card numbers and credentials to a server you don't control. The page looks and works normally, so nothing seems wrong.
Server-side scanning and periodic audits can't see this, because the theft happens in the customer's browser, in scripts that change between scans. Effective prevention watches every script's behavior on the live page in real time. It flags unauthorized DOM changes, form interception, and unexpected network calls before data leaves.
Prevention checklist
- Monitor every first- and third-party script's behavior on the live page, not just an approved list of sources.
- Detect unauthorized DOM changes, form interception, and keylogging as they happen in the browser.
- Alert on unexpected network calls sending form data to unknown destinations.
- Track script and security-header changes on payment pages for PCI DSS 6.4.3 and 11.6.1 evidence.
- Keep a change history so a compromised script can be caught, scoped, and proven for compliance.
Risk signals and how to respond
A trusted script starts reading form fields
Unexpected outbound requests from the page
A third-party script changes without warning
New scripts on checkout between audits
| Risk signal | What it may indicate | Response |
|---|---|---|
| A trusted script starts reading form fields | Formjacking or card skimming | Block the script and alert in real time |
| Unexpected outbound requests from the page | Data exfiltration to an attacker server | Flag the destination and cut the connection |
| A third-party script changes without warning | Supply-chain compromise | Diff the change and re-review before it runs |
| New scripts on checkout between audits | Unmonitored client-side risk | Continuously monitor, don't rely on periodic scans |
What it looks like in cside
Checkout script and header monitoring
cside tracks every script and security-header change on your payment pages, with evidence for PCI DSS.
How web skimming works
Magecart intercepts what customers type and exfiltrates it. cside catches the behavior in real time.
You've caught them all
Serra, the Hydra, the Leucrota, and the Aspidochelone are all captured. The bestiary is complete, and so is the hunt.
Fill in the raffle form to enter. It only takes a moment.
One entry per person. Winners are contacted after the draw.
Please leave the box exactly where you found it so the next player can find it too. Take one card and put the rest back.