Skip to main content

Aspidochelone: The Beast That Waits

The Aspidochelone looks like solid ground until sailors dock and drown. A trusted third-party script works the same way: safe until it skims your customers' card data.

You've captured the Aspidochelone, the final creature of the hunt. Scroll down to claim your reward.

Sailors mistook the Aspidochelone's shell for an island, moored to it, and were dragged under. A trusted script on your checkout is the same false ground: it loads without suspicion, then skims card numbers and hijacks forms through Magecart and formjacking.

How to prevent the Aspidochelone's attack

Magecart is client-side skimming: attackers inject or compromise a script on your site, often a trusted third party, and it copies what customers type into payment and login forms, then sends card numbers and credentials to a server you don't control. The page looks and works normally, so nothing seems wrong.

Server-side scanning and periodic audits can't see this, because the theft happens in the customer's browser, in scripts that change between scans. Effective prevention watches every script's behavior on the live page in real time. It flags unauthorized DOM changes, form interception, and unexpected network calls before data leaves.

Aspidochelone bestiary card: the island-fish representing Magecart and web-skimming attacks

Prevention checklist

  • Monitor every first- and third-party script's behavior on the live page, not just an approved list of sources.
  • Detect unauthorized DOM changes, form interception, and keylogging as they happen in the browser.
  • Alert on unexpected network calls sending form data to unknown destinations.
  • Track script and security-header changes on payment pages for PCI DSS 6.4.3 and 11.6.1 evidence.
  • Keep a change history so a compromised script can be caught, scoped, and proven for compliance.

Risk signals and how to respond

A trusted script starts reading form fields

What it may indicate Formjacking or card skimming
Response Block the script and alert in real time

Unexpected outbound requests from the page

What it may indicate Data exfiltration to an attacker server
Response Flag the destination and cut the connection

A third-party script changes without warning

What it may indicate Supply-chain compromise
Response Diff the change and re-review before it runs

New scripts on checkout between audits

What it may indicate Unmonitored client-side risk
Response Continuously monitor, don't rely on periodic scans

What it looks like in cside

cside PCI DSS dashboard showing weekly script and security-header changes on payment pages

Checkout script and header monitoring

cside tracks every script and security-header change on your payment pages, with evidence for PCI DSS.

diagram showing the formjacking and web-skimming attack flow that cside detects

How web skimming works

Magecart intercepts what customers type and exfiltrates it. cside catches the behavior in real time.

You've caught them all

Serra, the Hydra, the Leucrota, and the Aspidochelone are all captured. The bestiary is complete, and so is the hunt.

Fill in the raffle form to enter. It only takes a moment.

One entry per person. Winners are contacted after the draw.

Please leave the box exactly where you found it so the next player can find it too. Take one card and put the rest back.

Book a demo