This week, Sansec revealed that several Magento 1 websites had been compromised by hackers that had been able to inject credit card skimmers on pages of the checkout process. Sansecs tweet that seemed to indicate that the skimmer loader was available on facelook.no/en_US/pixel.js. If we visit the URL above, we obtain a (slightly) obfuscated file with the following content: a0a = [‘loud ‘,’lize ‘,’oudf ‘,’/wid ‘,’ item ‘,’e-st ‘,’//aj ‘, ‘.com ‘,’ckou ‘,’ntBy ‘,’i ‘,'”]
Source: https://antoinevastel.com/fraud/2020/09/20/analyzing-magento-skimmer.html

