{"id":13236,"date":"2018-09-20T04:32:09","date_gmt":"2018-09-20T04:32:09","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/"},"modified":"2018-09-20T04:32:09","modified_gmt":"2018-09-20T04:32:09","slug":"whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/","title":{"rendered":"Wha&#8217;s that smell? Oh, it&#8217;s Newegg cracked wide open by skimmers"},"content":{"rendered":"<p>Netizens buying stuff from Newegg had their bank card details skimmed for a month by hackers who stashed the Magecart toolkit on the dot-com&#8217;s payment pages.<\/p>\n<p>From August 16 to September 18, shoppers&#8217; sensitive card data was silently copied by the Magecart code during the site&#8217;s checkout process, and sent to neweggstats.com, which was created on August 13 by fraudsters to collect this information. The domain also had a digital certificate from Comodo to make it look nice and legit.<\/p>\n<p>The spyware would only appear at a certain point when completing a purchase, allowing it to evade researchers until it was finally discovered, reported, and removed on September 18. The malware was put there by miscreants compromising Newegg&#8217;s systems.<\/p>\n<p>And, yes, Magecart is the same malicious JavaScript toolset that was secretly deployed on <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/07\/12\/ticketmaster_breach_magecart\/\">Ticketmaster<\/a>&#8216;s website to nab revelers&#8217; card data, smuggled onto British Airways&#8217; site and app to snoop on roughly <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/09\/12\/feedify_magecart_javascript_library_hacked\/\">380,000 flight bookings<\/a>, and injected into <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/09\/12\/feedify_magecart_javascript_library_hacked\/\">Feedify&#8217;s libraries<\/a><\/p>\n<p><a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/09\/12\/feedify_magecart_javascript_library_hacked\/\">to compromise hundreds more e-commerce outfits.<\/a><\/p>\n<p>However, as infosec shop Volexity <a target=\"_blank\" href=\"https:\/\/www.volexity.com\/blog\/2018\/09\/19\/magecart-strikes-again-newegg\/\">explained on Wednesday<\/a>, the miscreants who targeted Newegg shrunk the card-siphoning Magecart code from the 22 lines deployed against BA to a mere eight lines, or 15 if the code is beautified.<\/p>\n<div class=\"CaptionedImage width_85\" readability=\"10\"><a href=\"https:\/\/regmedia.co.uk\/2018\/09\/20\/newegg_4.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2018\/09\/20\/newegg_4.jpg?x=648&amp;y=96&amp;infer_y=1\" alt=\"Newegg attack JavaScript - image by Volexity\" title=\"Newegg attack JavaScript - image by Volexity\" height=\"96\" width=\"648\"\/><\/a><\/p>\n<p class=\"text_center\">Part of the attack code, specifically, the JavaScript on the checkout page to nick payment card data &#8230; Click to embiggen<\/p>\n<\/div>\n<p>RiskIQ, which previously investigated the BA and Ticketmaster security breaches, <a target=\"_blank\" href=\"https:\/\/www.riskiq.com\/blog\/labs\/magecart-newegg\/\">also noted on Wednesday<\/a> that the rest of the approach against Newegg was the same: \u201cThe elements of the British Airways attacks were all present in the attack on Newegg: they integrated with the victim\u2019s payment system and blended with the infrastructure, staying there as long as possible.\u201d<\/p>\n<p>Newegg confirmed its systems had been hacked to squeeze Magecart into its webpages:<\/p>\n<blockquote class=\"twitter-tweet tw-align-center\" data-lang=\"en\" readability=\"6.6086956521739\">\n<p lang=\"en\" dir=\"ltr\">Yesterday we learned one of our servers had been injected with malware which was identified and removed from our site. We\u2019re conducting extensive research to determine exactly what info was obtained and are sending emails to customers potentially impacted. Please check your email<\/p>\n<p>\u2014 Newegg (@Newegg) <a href=\"https:\/\/twitter.com\/Newegg\/status\/1042466284577779712?ref_src=twsrc%5Etfw\">September 19, 2018<\/a><\/p><\/blockquote>\n<p>Here&#8217;s Volexity&#8217;s analysis of the data theft process:<\/p>\n<div class=\"boxout\" readability=\"11\">\n<p>To start off the script, window.onload = function() ensures all page elements are loaded prior to execution. The (\u2018#btnCreditCard.paymentBtn.creditcard\u2019).bind(\u201cmouseup touchend\u201d portion will then bind the button btnCreditCard within the class paymentBtn.creditcard to all mouseup and touchend events with the following actions defined below:<\/p>\n<ul>\n<li>Create a variable named dati containing all information entered within a form titled checkout.<\/li>\n<li>Take the data captured within the dati variable and create an array by serializing the form field names and values with the serializeArray() method.<\/li>\n<li>Takes the array of data and convert it to a JSON formatted string with the JSON.stringify() method.<\/li>\n<li>Submit the JSON string to the URL https:\/\/neweggstats.com\/GlobalData\/ within a POST request.<\/li>\n<\/ul>\n<\/div>\n<p>As for the aftermath, you know the drill: check your bank statements for any weird or unexpected purchases, and report them, especially if you shopped with Newegg between the above dates. Your card details were probably nicked, and may be used by crooks with a penchant for spending sprees using other people&#8217;s money. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1787\/-6625\/following-bottomlines-journey-to-the-hybrid-cloud?td=wptl1787\">Following Bottomline\u2019s journey to the Hybrid Cloud<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/09\/20\/newegg_hacked_magecart\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fresh from British Airways hack, Magecart strikes again Netizens buying stuff from Newegg had their bank card details skimmed for a month by hackers who stashed the Magecart toolkit on the dot-com&#8217;s payment pages.\u2026  READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":13237,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-13236","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Wha&#039;s that smell? Oh, it&#039;s Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Wha&#039;s that smell? Oh, it&#039;s Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-09-20T04:32:09+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"648\" \/>\n\t<meta property=\"og:image:height\" content=\"96\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Wha&#8217;s that smell? Oh, it&#8217;s Newegg cracked wide open by skimmers\",\"datePublished\":\"2018-09-20T04:32:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/\"},\"wordCount\":548,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/\",\"name\":\"Wha's that smell? Oh, it's Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg\",\"datePublished\":\"2018-09-20T04:32:09+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/09\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg\",\"width\":648,\"height\":96},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Wha&#8217;s that smell? Oh, it&#8217;s Newegg cracked wide open by skimmers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Wha's that smell? Oh, it's Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/","og_locale":"en_US","og_type":"article","og_title":"Wha's that smell? Oh, it's Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-09-20T04:32:09+00:00","og_image":[{"width":648,"height":96,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Wha&#8217;s that smell? Oh, it&#8217;s Newegg cracked wide open by skimmers","datePublished":"2018-09-20T04:32:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/"},"wordCount":548,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/","url":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/","name":"Wha's that smell? Oh, it's Newegg cracked wide open by skimmers 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg","datePublished":"2018-09-20T04:32:09+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/09\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers.jpg","width":648,"height":96},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/whas-that-smell-oh-its-newegg-cracked-wide-open-by-skimmers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Wha&#8217;s that smell? Oh, it&#8217;s Newegg cracked wide open by skimmers"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/13236","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=13236"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/13236\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/13237"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=13236"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=13236"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=13236"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}