Skip to content
MAGEKWIKScanner

Security research

Magento security blog

Technical breakdowns of what actually breaks Magento & Adobe Commerce stores — critical CVEs, card skimmers, and misconfigurations. Root cause, how attackers abuse it, real-world examples, and the exact fix. Sourced from the advisories and research, not marketing.

MALWARE & SKIMMERS CRITICAL Magento / Adobe Commerce scan.magekwik.com
critical Malware & skimmers

Backdoored and Abandoned Extensions: Supply-Chain Compromise of the Magento Ecosystem

Commercial Magento extensions run with core-level privilege on every request, which makes their license-check files an ideal home for a dormant backdoor. We dissect the 2025 Tigren/Meetanshi/MGS compromise, the 2022 FishPig/Rekoobe breach, and the polyfill.io skimmer — plus the exact grep and CSP checks to find and shut them down.

5 min read