How WooCommerce card skimming malware works
Web skimming, sometimes described as Magecart-style activity, targets ecommerce checkout processes. Malicious JavaScript can read information entered into a compromised payment page and transmit selected data to infrastructure controlled by the attacker.
The malicious code may be inserted into WordPress files, a theme, a plugin, the database or a third-party script loaded by checkout. An attacker can also alter the payment flow or inject convincing additional fields. This means an order appearing successfully in WooCommerce does not prove the browser was shown only legitimate code.
Payment-page security requires particular care because scripts executing in the customer's browser can affect sensitive information. PCI Security Standards Council guidance places specific emphasis on authorising payment-page scripts, checking their integrity and detecting unauthorised changes.
How to check WooCommerce for a credit card skimmer
If customers report suspicious card activity after purchasing, treat the report seriously without assuming the website is automatically the cause. Preserve evidence and inspect the checkout before making changes that could destroy useful information.
Review the browser developer tools and page source for scripts, domains or checkout fields that should not be present. Compare the current checkout with a known clean version and inspect recently modified theme, plugin and JavaScript files. Check database content for injected scripts and review third-party resources loaded by checkout.
Test from both desktop and mobile because malicious behaviour can be conditional. Where relevant, compare what ordinary visitors receive with the response available to Google's crawlers through Search Console inspection. Also check Search Console Security Issues and Pages reports and run a site:yourdomain.co.uk search for signs of a wider compromise.
The free WordPress security scanner provides another external check, but checkout skimming requires close inspection of the code and resources that actually execute in the browser.
How to clean a WooCommerce skimmer safely
- Preserve the evidence. Take a complete backup of the files and database before cleaning and retain an untouched copy of the compromised store. Preserve relevant server and security logs where available.
- Protect customers while investigating. If checkout may be compromised, stop exposing customers to the affected payment flow until it has been examined and secured.
- Identify both the skimmer and its entry point. Review changed files, database injections, plugins, themes, administrator accounts, hosting access and third-party scripts. Removing the visible JavaScript without closing the route used to install it leaves the store vulnerable to reinfection.
- Restore trusted code. Remove confirmed malicious injections, replace altered WordPress core files and reinstall affected plugins or themes from trusted sources. Verify every script expected on the checkout page.
- Rotate access credentials. Change WordPress passwords, hosting access, database passwords, FTP or SFTP credentials, relevant service keys and the WordPress salts in wp-config.php.
- Escalate the payment incident appropriately. If payment-card data may have been exposed, contact your payment service provider or acquirer promptly and follow the incident and PCI DSS requirements applicable to your payment setup.
- Retest before reopening checkout. Inspect the rendered payment page, network requests, files and database again and confirm the original access route has been closed.
Hacked Site Rescue is £349 fixed price for investigation and malware removal.
Reducing the risk of WooCommerce skimmer reinfection
Keep WooCommerce, WordPress, themes and plugins updated, and completely remove unused extensions. Restrict administrator access, require strong unique passwords and two-factor sign-in, and use lower-privilege accounts for people who do not need control of plugins or site code.
For checkout security, maintain an inventory of scripts that are supposed to run on payment-related pages and investigate unexpected additions or changes. Payment implementations differ, so merchants should follow current guidance from their payment provider and the PCI Security Standards Council for their environment.
File integrity checks and reliable off-server backups give you additional evidence and recovery options. Because WooCommerce is an ecommerce platform, ongoing support requires Premium Care, while Web Support Services care plans as a range start from £59 a month.