Dormant Magento Supply Chain Attack Hits Up to 1,000 Merchants
21 extensions from Tigren, Magesolution, and Meetanshi carried six-year-old card-stealing malware—audit your plugins for the fake license and strengthen runtime protections.
Researchers at Sansec uncovered a supply chain attack infecting 21 Magento extensions from Tigren, Magesolution (MGS), and Meetanshi—malware that lay dormant for six years but activated last month—impacting an estimated 500–1,000 online merchants. The JavaScript payload runs in visitors’ browsers to steal payment card and other sensitive data in real time. If you operate e-commerce sites on Magento, audit your extensions for the fake license identified by Sansec, verify plugin integrity, and deploy runtime protections to detect malicious behavior.
Source:
Sansec research report

