Magecart’s 2024 Resurgence: Skimming in the Polyfill.io Aftermath
Through 2024, digital skimming returned to threat reports' front pages: Magecart-style attacks compromised hundreds of storefronts via compromised third-party JavaScript, supply-chain infections like polyfill.io's June domain takeover injected malicious scripts into vast numbers of pages, and PCI DSS 4.0's script-integrity requirements (6.4.3 and 11.6.2) approached their March 2025 enforcement deadline. This survey digests the modern skimming kill chain — injection, exfiltration, and evasion — the major 2024 campaigns, and the compliance clock turning client-side risk into boardroom math.
