Proprietary · · 33 days
Volusion storefront script skimmed payments
A Volusion storefront JavaScript path loaded a Magecart skimmer from Google Cloud Storage. Confirmed scope landed in the low thousands of shops, with later fraud reporting tying hundreds of thousands of card records to the breach.
The Volusion breach surfaced from a checkout page, not from a malware alert. In October 2019, researcher Marcel Afrahim was shopping on the Sesame Street Live Store, a Volusion-hosted merchant, when he noticed the checkout loading an odd JavaScript file from storage.googleapis.com/volusionapi/resources.js. Google Cloud Storage had been abused to host malicious code before, which is what made it worth a second look. The file was reached through Volusion's normal storefront JavaScript path by way of /a/j/vnav.js, a script dressed up as jQuery UI navigation code, so it read as part of the platform rather than a third-party add-on any single merchant had chosen.
Afrahim searched publicwww for the same a/j/vnav.js path and found 6,593 sites carrying it. Trend Micro later described the injected code as a Magecart skimmer active on 3,126 Volusion-hosted shops, with data showing activity from September 7, 2019, while Gemini Advisory and other reporting connected roughly 6,589 to 6,593 domains to the compromised path. Response headers Afrahim captured pointed to September 12, with modification timestamps hinting at earlier activity. Some early reports speculated about up to 20,000 stores because Volusion's customer base was larger, but the confirmed infected-domain counts were lower.
The skimmer copied payment-form data, encoded it with base64 plus a serialization and shift step to defeat casual deobfuscation, stashed it in browser sessionStorage under the innocuous key ___utmz_opt_in_out, and posted it to volusion-cdn.com/analytics/beacon as what looked like analytics traffic. The exfiltration domain mimicked Volusion's own CDN naming closely enough to blend into a noisy checkout page; it sat on Vultr at 66.42.76.145 behind WhoisGuard registration privacy. Trend Micro assessed the activity as likely Magecart Group 6, also known as FIN6, based on victim selection, exfiltration-domain style, and similarities to the earlier British Airways and Newegg skimmers. Volusion said it resolved the issue within hours of notification and that a limited portion of customer information from a subset of merchants was compromised.
The later fraud story is related but should not be confused with the store count. Gemini Advisory found 239,000 compromised card-not-present records offered for sale after the incident, and estimated that potential exposure could reach nearly 20 million records if the average small-merchant breach scale held across the confirmed Volusion merchant set.
Appendix · Affected releases
- Trend Micro reported 3,126 actively affected shops; Gemini Advisory later confirmed 6,589 domains connected to the compromised domain, close to the 6,593 pages found by Marcel Afrahim and cited by ZDNet/TechHQ.
- Gemini Advisory found 239,000 card-not-present records offered for sale and modeled potential exposure at nearly 20 million records; that estimate is not the confirmed infected-store count.
References
- Magecart Card Skimmers Injected Into Online Shopstrendmicro.com
- Breached Volusion Card Data Surfaces in Dark Webgeminiadvisory.io
- Sesame Street & Volusion customers are compromised; how the cookie monster is stealing CC numbersmedium.com
- 6,500 online stores breached in Volusion supply-chain attacktechhq.com
- Magecart Attack on Volusion Highlights Supply Chain Dangersdarkreading.com
- How A Magecart Attack Works And How Volusion Was Hackedoptimum7.com
Source record: proprietary/volusion/meta.yaml