There's a new way hackers are stealing your card details — and it's invisible to most security tools
If you've bought something online recently — Flipkart, Amazon India, any smaller shopping site — and paid by card, here's something uncomfortable: a new type of malicious script has been found that can steal your card number, CVV, and expiry date in real time, and it bypasses the standard security protection that 90% of e-commerce sites use to block exactly this kind of attack.
The attack is called a WebRTC skimmer. Security researchers discovered it on compromised e-commerce sites running Magento and Adobe Commerce — two of the most widely used platforms for building online shops globally, including thousands of Indian e-commerce stores.
The reason this is alarming: it doesn't just steal data. It steals data in a way that avoids detection by both the website's own security system and the network security tools watching for suspicious activity.
Let's break this down simply — what is a payment skimmer?
A payment skimmer is malicious code secretly injected into a shopping website. When you reach the checkout page and type in your card details, the skimmer silently copies everything you type — card number, expiry date, CVV, billing address — and sends it to the attacker before you even hit "Pay Now."
The website processes your payment normally. You see a confirmation. You have no idea anything went wrong. But somewhere, someone now has a complete copy of your card details.
Card skimming attacks on online shops have been around for years. The security industry has developed defences against them. The most important one is something called Content Security Policy, or CSP.
What is CSP — and why did everyone think it was enough?
Content Security Policy (CSP) is a security instruction that a website sends to your browser. It essentially tells your browser: "This website is only allowed to load code from these specific trusted locations. If you see any code trying to load from anywhere else — block it."
For a skimmer to steal your data, it normally needs to send that data to an attacker's server somewhere on the internet. CSP was designed to catch exactly this: if malicious code tries to send data to an unauthorized server, CSP blocks the connection.
This worked well for years. When a skimmer tried to upload your card details to a random server in another country, the browser would block the request because that server wasn't on the website's approved list. Security teams felt reasonably protected.
The new WebRTC skimmer breaks this protection entirely.
How WebRTC breaks CSP — explained without jargon
WebRTC stands for Web Real-Time Communication. It's the browser technology that powers video calls — Google Meet, Zoom in the browser, WhatsApp Web video calls, all of it runs on WebRTC. It allows your browser to make direct, peer-to-peer connections to other computers.
Here's the critical technical detail: Content Security Policy does not apply to WebRTC connections. This isn't a bug — it was a deliberate design decision made when WebRTC was built, because WebRTC was meant for legitimate real-time communication and the connection model is fundamentally different from loading web resources.
The new skimmer exploits this gap. Instead of trying to send stolen card data over a normal web request (which CSP would block), it establishes a WebRTC DataChannel — a direct, encrypted connection to the attacker's server. CSP sees nothing wrong, because CSP doesn't govern WebRTC. The data flows out through a channel that the browser's security policy doesn't monitor.
To make detection even harder, WebRTC uses encrypted UDP traffic rather than standard HTTP. Most network security monitoring tools that watch for suspicious HTTP traffic won't catch WebRTC data exfiltration. The stolen card details travel out encrypted, over a protocol that looks like legitimate video call traffic.
How the attack actually works on a compromised site
Here's the sequence of what happens when you shop on an infected site:
First, the attackers compromise the e-commerce site — typically through a vulnerability in Magento or Adobe Commerce, the software running the store's backend. They upload a malicious file to the server.
Second, when you visit the checkout page, the site loads normally — but the malicious code is quietly running in the background. You see a legitimate-looking payment form.
Third, as you type your card details, the skimmer intercepts each keystroke. It assembles your complete card information in memory.
Fourth — and this is where the WebRTC bypass matters — instead of sending your data over a normal web request that CSP would catch, the skimmer establishes a WebRTC DataChannel directly to the attacker's server. The connection is encrypted, the traffic looks like peer-to-peer communication, and it bypasses every CSP rule on the page.
Your card details arrive at the attacker's server in seconds. The payment page continues loading normally, your transaction goes through, and you get a confirmation email. Nothing looks wrong.
Why Indian online shoppers should care specifically
India's e-commerce market processed over $60 billion in transactions in 2025. Card payments — credit cards, debit cards — remain significant alongside UPI. A large portion of Indian e-commerce runs on platforms like Magento and WooCommerce, which are common targets for these kinds of injections.
The attack isn't limited to large sites. Smaller regional e-commerce stores — clothing brands, electronics retailers, specialty goods sites — are often more vulnerable because they have less dedicated security staff monitoring for code injections. If you regularly shop at smaller Indian online stores and pay by card, your exposure is real.
UPI payments (GPay, PhonePe, Paytm) don't carry the same risk from this specific attack — because with UPI, your card details never actually enter a form on the website. The payment happens in your UPI app directly. This is one of the genuine security advantages of UPI over card entry for online purchases.
If you're shopping on a site that asks you to type your card number manually into a web form — that's where skimmer risk exists. Virtual cards from your bank, or paying through wallet services that tokenize your card details, reduce your exposure.
What should e-commerce site owners do?
For developers and site owners running Magento or Adobe Commerce stores in India, there are concrete steps:
Keep your Magento/Adobe Commerce installation patched and updated — skimmers get in through known vulnerabilities that are already fixed in updates that haven't been applied. Many compromised sites are running outdated versions.
Implement Subresource Integrity (SRI) checks on all JavaScript files loaded by your site. SRI ensures that if a JavaScript file is modified (by an attacker injecting skimmer code), the browser rejects it because the file no longer matches its expected cryptographic hash.
Use a Web Application Firewall (WAF) with rules specifically designed for Magento attack patterns. Cloudflare, Sucuri, and Astra Security all offer WAF products used by Indian e-commerce sites.
Monitor your site's file system for unauthorized changes. Skimmer injections leave traces in modified server files — automated file integrity monitoring can catch these.
Specifically for WebRTC: consider implementing a strict WebRTC policy at the network level, restricting WebRTC connections to known legitimate origins. This won't stop all variants of the attack but raises the barrier significantly.
What shoppers can do right now
Use UPI wherever possible for online payments — GPay, PhonePe, Paytm UPI. If a site offers UPI, use it instead of typing card details into a web form.
For card payments, use virtual card numbers. HDFC, ICICI, SBI, and Axis Bank all offer one-time or limited-use virtual card numbers through their apps. Even if a skimmer steals the virtual card number, it can't be used for additional transactions beyond what you authorized.
Check your bank statement weekly, not monthly. Skimmer fraud often starts with small test charges before larger fraudulent transactions. Catching a ₹1 or ₹5 test charge quickly can save you from a larger loss.
Browser extensions like Privacy Badger or uBlock Origin can block some WebRTC data leaks — they're not perfect defences but add a layer of protection.
TamilTech's take
CSP bypasses through WebRTC aren't new in academic security research, but finding them deployed in real-world payment skimmers on live e-commerce sites is a step up in attacker sophistication. This tells us that the people running these operations are technically capable enough to implement novel attack vectors — they're not just copy-pasting old skimmer code.
The safest personal defence for Indian shoppers is genuinely simple: use UPI. Not because card payments are universally compromised, but because UPI removes the specific attack surface that skimmers exploit. Your card details never enter a web form. Skimmers have nothing to steal.
For the e-commerce ecosystem: patching and file integrity monitoring remain the most effective defences. A skimmer can't run code on your checkout page if it can't get injected in the first place.




Comments (0)
Be the first to comment!