Security researcher Willem de Groot , as a result of the infrastructure breach, the attackers were able to insert malicious code into the web analytics system and an open platform for generating interactive web forms . The JavaScript code substitution led to the compromise of 4684 websites using these systems ( — Picreel and — Alpaca Forms).
The injected collected information about the completion of all web forms on the sites and could also lead to the interception of payment information and authentication parameters. The intercepted information was sent to the server font-assets.com disguised as image requests. There is currently no information on how precisely the infrastructure of Picreel and the CDN network for delivering the Alpaca Forms script were compromised. It is only known that during the attack on Alpaca Forms, scripts delivered through the Cloud CMS content delivery network were substituted. was disguised as a data array in the of the script (the code decryption can be viewed ).
Among the users of the compromised projects are many large companies, including Sony, Forbes, Trustico, FOX, ClassesUSA, 3Dcart, Saxo Bank, Foundr, RocketInternet, Sprit, and Virgin Mobile. Considering that this is not the first attack of this kind (see the with the substitution of the StatCounter counter), website administrators are advised to be very cautious about placing third-party JavaScript code, especially on pages related to payments and authentication.
Source: opennet.ru
