Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In a campaign observed in 2020, attackers injected payment-skimming JavaScript into shopping sites hosted on Microsoft IIS and running ASP.NET 4.0.30319. Dark Reading published its brief on July 7, 2020, drawing on Malwarebytes Labs research published July 6. The reporting described more than a dozen compromised sites—not a weakness in ASP.NET itself and not evidence that every ASP.NET site was affected.
What happened in the ASP.NET skimmer campaign?
Malwarebytes analyst Jérôme Segura said the activity likely began in April 2020. Malwarebytes reported that hivnd[.]net, one of the campaign’s infrastructure domains, was registered on April 10, 2020.
Researchers identified more than a dozen compromised websites through open-source intelligence. The organizations included sports groups, health and community associations, and a credit union. Some had already removed the malicious code by the time Malwarebytes published its analysis, so the count was an investigation finding rather than a complete census of victims.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Every identified site was reported to be hosted on Microsoft IIS, running ASP.NET version 4.0.30319, and offering a shopping portal. Dark Reading described that framework version as no longer officially supported and as containing multiple flaws, attributing the characterization to the researchers. That observation does not establish how the attackers gained access, nor does it show that ASP.NET 4.0.30319 caused the compromises.
#1 Best Overall
- MSR605X Reader Writer Encoder All 1/2/3 Tracks
- Work USE USB Power Supply
- Functions: Read,Write, Copy, Erase, Edit.
- Free 20pcs Blank Cards
How does a credit-card skimmer get onto an ASP.NET website?
The incident sources point to a prior compromise of the website or its development and hosting environment, followed by alteration of client-side JavaScript. The skimmer ran in a shopper’s browser during checkout, where it could read information entered into payment forms. The reporting did not identify one ASP.NET component or one JavaScript library as the universal entry point.
Code hidden inside an existing JavaScript library
In most observed cases, attackers inserted the skimming logic directly into a legitimate JavaScript library already served by the site. This approach can blend malicious statements into a file that developers and browser tools expect to load, making a simple filename or dependency review less reliable.
An altered library that loads code remotely
Some sites served a modified legitimate library that fetched the skimmer from a remote domain. This separates part of the malicious payload from the site’s own files and can make the injected code take different forms over time.
Rank #2
- MSR90 is a USB emulation keyboard interface that not need any driver or software,USB simply plug and play
- Reads up to 3 tracks of information,can reads ISO7811, AAMVA, CA DMV and most other card data formats
- Threaded inserts for mounting. LED indicator, green light is on when connecting,green light blinks when cards swiped
- Bi-directional swipe reading, superior reading of high jitter, scratched, and worn magstripe cards, reliable for over 1,000,000 card swipes
- Configuration software makes configuration changes easy,works with: Windows OS and Mac OS
| Observed method | What the shopper’s browser received | Why it complicated detection |
|---|---|---|
| Embedded injection | Skimming statements inserted into an existing JavaScript library | The trusted file still had a familiar name and role, but its contents had changed |
| Remote load | An altered local library that requested additional code from a campaign domain | Part of the payload was outside the merchant’s normal JavaScript inventory |
Malwarebytes said there was no single JavaScript library being targeted. The code varied between victims, which further reduced the value of looking for only one fixed text pattern.
What information did the skimmer steal?
The code searched for credit-card numbers and also attempted to identify passwords. Segura assessed that the password-seeking method “appears to be incorrectly implemented,” so the report does not establish successful password theft in every case.
Malwarebytes described the captured data as being encoded and sent in an HTTP GET request to the same infrastructure used by the campaign. The request used a filename made to resemble a GIF image, an old but recognizable way of disguising data exfiltration as an ordinary asset request.
Rank #3
- 1/2/3 Tracks Read/Write/Copy/ Erase Hico/Loco (300~4000 oe)Mag Card
- Bluetooth and USB interface works with Computers and mobile/Tablet
- Free Software For Windows 98/2000/XP/Vista/7/8/10 (32&64), MAC OS
- APP Download "EasyMSR" from "Google Play" or "App Store" for Android Mobile/Tablet or iPhone,iPad Using
- Smallest Size: 5.4*1.4*1.4 Inch
Were all ASP.NET sites affected?
No. The researchers found more than a dozen affected websites, and all of those identified victims shared the observed IIS, ASP.NET 4.0.30319, and shopping-portal characteristics. That is a description of the sample, not a claim that all ASP.NET installations—or even all sites on that version—were compromised.
Recommended Free Tools
The available reporting concerns a campaign investigated in 2020. It does not establish that the same infrastructure or code is active now, and the listed indicators should not be treated as a current blocklist or proof of present malicious activity.
Historical indicators reported by Malwarebytes
Malwarebytes listed these domains and address as indicators associated with the investigation:
Rank #4
- COMPATIBILITY: Works with multiple credit card terminal models including VeriFone M400 & M440 stationary terminals
- QUICK DETECTION: Takes only seconds to verify if credit card terminals are free from unauthorized skimming devices
- SECURITY TOOL: Helps protect payment systems by identifying potential tampering or foreign objects on card readers
- EASY TO USE: Simple physical verification process requires no technical expertise or special training
- VERSATILE DESIGN: Available in different models to accommodate various terminal types including M400 for Verifone M400 / M440. The MX 900 for Verifone MX900/MX925, Ingenico Lane (3000/5000/7000), Pax PX7 and more.
idpcdn-cloud[.]comjoblly[.]comhixrq[.]netcdn-xhr[.]comrackxhr[.]comthxrq[.]comhivnd[.]net31.220.60[.]108
The domains are shown in bracketed, defanged form so they are not accidentally visited. Malwarebytes also published a regular expression for finding the injection patterns it observed. Both that expression and the indicators are historical investigation artifacts; their current status is unknown.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the incident means for site owners
ASP.NET was the hosting context, not the explanation
The campaign demonstrates that attackers can target the browser-facing code of a less-fashionable or specialized e-commerce site. It does not support blaming ASP.NET as the root cause. Segura wrote: “Attackers do not need to limit themselves to the most popular e-commerce platforms. In fact, any website or technology is fair game, as long as it can be subverted without too much effort.”
A checkout can be compromised even when the payment processor is separate
A merchant may hand payment authorization to a third party while still collecting card details in its own page. Malicious JavaScript running before that handoff can read fields as a customer types, so a separate processor does not automatically prevent browser-side theft.
Best Value
- Package Dimensions: 2.4 cms (L) x 9.9 cms (W) x 2.4 cms (H)
- Product Type: Memory Reader
- Package Quantity: 1
- Country Of Origin: China
Do not treat old indicators as a complete response plan
The incident sources do not provide current, official Microsoft or payment-card remediation instructions. Organizations investigating a similar symptom should use current guidance from their hosting, framework, payment, and incident-response providers rather than assuming that deleting one suspicious domain or matching one old regular expression has removed the attacker’s access.
Malwarebytes said it contacted remaining affected organizations so they could identify the breach and harden their infrastructure. It also stated that its customers were protected by its web-protection technology and Browser Guard extension. Those are vendor statements about its products, not independent evidence that a consumer tool removes malicious code from a merchant’s server.
Quick Recap
What readers should take away
- The report describes a 2020 JavaScript-skimming campaign, not a current threat assessment.
- Researchers identified more than a dozen shopping sites hosted on IIS and running ASP.NET 4.0.30319.
- The skimmer was embedded in existing JavaScript in most cases or loaded from a remote domain in some cases.
- It sought payment-card data and attempted password detection, although the password logic appeared incorrectly implemented.
- Nothing in the reporting shows that all ASP.NET sites were affected or that the framework version alone explains the initial compromise.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

