Cybercriminals used the credit card stealer reinfector to reinfect the websites and continue to steal personal and financial data. The code is hidden inside the default configuration file (config.php) of Magento installs. It is included on the main index.php and is loaded with every page visited by the users, this process ensures that the code is re-injected into multiple files of the website. The malicious code was stored on Pastebin, this choice allows attackers to remain under the radars.”]
Source: https://securityaffairs.co/wordpress/73770/malware/magento-credit-card-stealer-reinfector.html