PrestaShop skimmers
Detecting credit card skimmers in PrestaShop stores
A skimmer copies card data while the customer pays. The store works and orders come in, so it is often noticed only through customer complaints.
The problem
The code sits in a template, not in a PHP file.
On 17 February 2026 PrestaShop warned stores about a loader hidden in head.tpl: a base64-encoded address, fetched with XMLHttpRequest and run with Function.
In July 2022 an SQL injection let attackers create blm.php in the store root and insert a fake payment form into the checkout.
How it works
Signatures built on published incidents.
- 1
Templates included
The scan also reads
.tpland.twigfiles, besides PHP and JavaScript. - 2
Loader structure
We look for the encoded address, the request and the execution of the response together: a lone
atoborXMLHttpRequestis not enough. - 3
New files
A PHP file in the root or an unknown module shows up at the next scan; if it holds an executable call, the alert is critical.
In detail
Tested on real stores.
- Inert samples: the loader sits inside a Smarty comment and points to
example.invalid - Detected even when the store was already infected at the first scan
- Detected during a core upgrade too
- No false positives across 37,172 files of a clean PrestaShop 9.2 store
- The alert closes on its own once the file is clean again
FAQ
Frequently asked questions
Do you catch every skimmer?
No. Signatures cover documented structures. Variants obfuscated differently can slip through, and core integrity remains the second line.
Do you read whole files?
We read the first MiB of each checked file, without running it and without opening the addresses it contains.
Related features
Goes well with
Try it on your clients' sites.
During the beta we let in a few agencies at a time and set up the first sites with you.