Visa Payment Fraud Disruption warns of a new JavaScript skimmer dubbed Pipka used to siphon payment data from e-commerce merchant websites. Unlike other skimmers, Pipka has the ability to remove itself from the compromised HTML code after execution, in an effort to avoid detection. The skimmer software is able to capture payment account number, expiration date, CVV, and cardholder name and address, from the checkout pages of the targeted sites. Data captured by the skimmer is base64 encoded and encrypted using ROT13 cipher. Pipka also uses a new technique to hide the exfiltration of harvested data.”]
Source: https://securityaffairs.co/wordpress/93876/malware/pipka-skimmer.html