Exploitation of Outdated Stripe API to Authenticate Stolen Payment Cards in Web Skimmer Operation
Security analysts caution against a sophisticated web skimmer initiative that exploits an outdated application programming interface (API) provided by payment service provider Stripe to validate stolen payment details before extracting them.
“By using this strategy, the hackers verify that only legitimate card data is transmitted to them, enhancing the effectiveness of the scheme and potentially increasing its stealthiness,” stated Pedro, a researcher from Jscrambler.
“By using this strategy, the hackers verify that only legitimate card data is transmitted to them, enhancing the effectiveness of the scheme and potentially increasing its stealthiness,” stated Pedro, a researcher from Jscrambler.
