Sports trading card and collectible company Topps.com issued a data breach notification stating that it was affected by an attack that possibly exposed payment and address information of its customers. This type of attack is called a MageCart attack, when attackers inject a malicious script into a site’s checkout or cart pages. When a visitor enters their payment information, this script will copy the submitted data and send it to a remote server for the attackers to collect. On January 9th, 2019, Topps upgraded the software used to run their site and removed the malicious script.
Source: https://www.bleepingcomputer.com/news/security/toppscom-sports-collectible-site-exposes-payment-info-in-magecart-attack/

