Massive E-commerce Supply Chain Attack Exposes Millions
2025-05-05

Security researchers have uncovered a supply chain attack targeting hundreds of e-commerce sites, including a $40 billion multinational company. Attackers compromised at least three software providers, implanting malware that lay dormant for six years before activating in recent weeks to steal payment card information and other sensitive data. At least 500 sites are affected, with the true number potentially double that. The malware allows attackers to execute arbitrary code in visitor browsers, enabling remote code execution and data theft. Affected software providers include Tigren, Magesolution, and Meetanshi, all offering Magento-based software.
Tech