MultiCmsManager

PrestaShop skimmers

Detecting credit card skimmers in PrestaShop stores

A skimmer copies card data while the customer pays. The store works and orders come in, so it is often noticed only through customer complaints.

The problem

The code sits in a template, not in a PHP file.

On 17 February 2026 PrestaShop warned stores about a loader hidden in head.tpl: a base64-encoded address, fetched with XMLHttpRequest and run with Function.

In July 2022 an SQL injection let attackers create blm.php in the store root and insert a fake payment form into the checkout.

How it works

Signatures built on published incidents.

  1. 1

    Templates included

    The scan also reads .tpl and .twig files, besides PHP and JavaScript.

  2. 2

    Loader structure

    We look for the encoded address, the request and the execution of the response together: a lone atob or XMLHttpRequest is not enough.

  3. 3

    New files

    A PHP file in the root or an unknown module shows up at the next scan; if it holds an executable call, the alert is critical.

In detail

Tested on real stores.

  • Inert samples: the loader sits inside a Smarty comment and points to example.invalid
  • Detected even when the store was already infected at the first scan
  • Detected during a core upgrade too
  • No false positives across 37,172 files of a clean PrestaShop 9.2 store
  • The alert closes on its own once the file is clean again

FAQ

Frequently asked questions

Do you catch every skimmer?

No. Signatures cover documented structures. Variants obfuscated differently can slip through, and core integrity remains the second line.

Do you read whole files?

We read the first MiB of each checked file, without running it and without opening the addresses it contains.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.