Web security firm Sucuri has detailed a recent attack on a site that experienced a spate of credit card fraud. The attackers had hidden malicious JavaScript code inside a system file. The most significant giveaway sign on the WordPress CMS was that a PHP file was added to ensure the malicious code loaded, Sucuri said. This is unusual because most attacks on ecommerce systems involve appending code at the end of a file, a technique which is effective but easier for defenders to spot. Its a reminder that all ecommerce shops need careful defence.”]

