Imagine a small WooCommerce shop owner. Sales were steady. Chargebacks ticked up half a percent over a few weeks, and nobody flagged it. Then a customer’s bank called. Then another. Then the merchant processor started asking pointed questions about the checkout page.

The answer was a free plugin called Funnel Builder. A critical bug had been actively exploited to inject JavaScript into WooCommerce checkout pages, quietly siphoning credit card numbers as customers typed them. The cybersecurity stack around the store was fine. MFA was on. The firewall was logging. None of it mattered, because the attacker never needed to log in. They needed the plugin to do its job and ship their code along with it.

That’s the story of the week, and the lesson is bigger than WordPress. Attackers want something specific, and a password rarely stands between them and it.

WooCommerce checkout page logo with skimmer overlay concept
The Funnel Builder plugin bug let attackers inject card-stealing JavaScript directly into checkout pages.

The Login Stopped Being the Prize

Look at the rest of the week’s headlines and the pattern jumps out.

The REMUS infostealer, profiled this week by Flare, has reorganized its entire business model around session theft. Stolen browser cookies and authentication tokens now command higher prices on criminal markets than passwords do. A live session bypasses MFA. It bypasses anomaly detection that fires on a new login. It looks like the legitimate user because, technically, it is them, just with the cookie now in someone else’s browser.

The node-ipc npm package was compromised this week with credential-stealing malware injected into newly published versions. Developers running install scripts on their own laptops handed up environment variables, SSH keys, and tokens to whoever pushed the malicious release. The attackers didn’t phish anyone. They published a package update.

And Microsoft this week reversed course and confirmed that Edge will stop loading saved passwords into process memory in cleartext at startup. The previous behavior, which the company had defended as “by design,” meant that any process with the right level of access could read every password the browser had ever saved. No keylogger required. No session hijack. Just memory inspection.

Each of these stories has the same shape. The attacker skipped the part where they had to make the user type a password into the wrong box. They went directly for what the password was supposed to protect: the card number, the live session, the saved secrets in memory, the developer’s already-authenticated tokens.

Your Cyber Security Stack Doesn’t See This Crime

Here is the awkward truth. A firewall watches traffic on the way in. Brute-force protection watches who tries to log in. Threat detection rules look for known signatures. None of those controls watch what your trusted plugin’s JavaScript is sending out to a domain you’ve never heard of.

The Funnel Builder skimmer didn’t need to evade anything. It rode along inside a piece of code the site explicitly trusted. The same is true of the node-ipc supply chain attack: every developer’s machine ran the malicious code with full local privileges because that’s what you do with a dependency you’ve installed.

Defense in depth is the cliché, but in this context it has a specific meaning. You stop assuming that the things you installed remain the things you installed. You watch what they do, not just whether they were on the list when you started.

Infostealer malware concept image showing browser data exfiltration
Modern infostealers prioritize session tokens over passwords because tokens bypass MFA entirely.

What to Actually Do Before Your Checkout Page Becomes Evidence

A few concrete moves, none of which require buying anything.

Lock down what your checkout page is allowed to load. A strict Content Security Policy that whitelists only your payment processor’s domain will block injected skim scripts from exfiltrating data, even if the attacker already won at the plugin layer. If your CSP refuses to add a domain you don’t recognize, your team gets a tripwire instead of a chargeback notice.

Isolate the actual card entry. Hosted payment fields or iframe-based card capture from your processor mean the card number never touches your server’s DOM in the first place. The skimmer can run all it wants. It has nothing to read.

Treat plugin and dependency updates as a change to your code, not a maintenance task. File integrity monitoring on your WordPress wp-content directory and your application’s node_modules will tell you when a “trusted” package suddenly looks different. Unattended auto-updates feel safe right up until they aren’t.

Keep an outbound view. Your egress logs from web frontends, build servers, and developer laptops are the cheapest threat detection you have. A checkout page calling out to a freshly registered .top domain, or a CI runner suddenly hitting Pastebin, is the actual signal that the boring controls missed.

Pull session lifetime down. If REMUS-style infostealers are now the default, your tolerance for weeks-long persistent sessions on admin panels, source control, and cloud consoles needs to drop. Short tokens, hardware-bound credentials where you can get them, and re-authentication on sensitive actions break the resale value of a stolen cookie. That’s a meaningful threat-protection upgrade for very little engineering effort.

Rotate dev credentials on a schedule, not when something looks wrong. The node-ipc victims who rotated their npm tokens, AWS keys, and SSH credentials within a day of the disclosure had a bad week. The ones who didn’t have a much longer one ahead. Build the rotation into your incident response plan now, while the playbook is theoretical.

The Boring Controls Earn Their Keep

Pwn2Own Berlin handed out $385,750 on day two for fifteen zero-days in Exchange, Windows 11, and Red Hat. THORChain lost $10.7 million from a single vault compromise. Big numbers and dramatic exploits get the headlines. But the small WooCommerce store losing customer cards through a plugin nobody patched, and the developer who ran npm install at the wrong moment, are the ones that show up in court filings and PCI penalty letters.

Security hardening for the next year is going to be deeply unsexy. CSP headers. Payment iframes. Egress monitoring. Token rotation. Shorter session lifetimes. None of it will make a vendor’s slide deck. All of it will save someone a bad phone call from their bank.

The password isn’t the prize anymore. Plan accordingly.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.