# Hackers Are Hiding Malware in 1-Pixel SVGs — What Every Designer Needs to Know About SVG Security in 2026
> A 1×1 pixel SVG just stole credit card data from 99 e-commerce stores. SVG-based attacks are up 50x since 2024. Here's how the attack works, why Adobe still hasn't patched it, and how to protect yourself.
**Source:** https://vectosolve.com/blog/svg-security-polyshell-malware-designers-2026
**Author:** Robin Monteiro (Founder of VectoSolve)
**Published:** 2026-04-12
**Category:** Technology
**Reading time:** 12 min read
**Tags:** svg security, svg malware, polyshell, magento hack, credit card skimmer, xss, svg sanitization, web security, magecart, e-commerce security
---
## A Single Pixel Stole Millions in Credit Card Data
On April 7, 2026, security researchers at [Sansec](https://sansec.io/research/svg-onload-magecart-skimmer) discovered something chilling: **99 Magento e-commerce stores** had been silently compromised by a credit card skimmer hidden inside a **1×1 pixel SVG element**. The entire malware payload — the fake checkout form, the data encryption, the exfiltration logic — was encoded in a single `onload` attribute.
No external scripts. No suspicious network requests to flag. Just one invisible pixel, quietly stealing every credit card number entered on the checkout page.
The entry point? A vulnerability called **PolyShell** ([APSB25-94](https://helpx.adobe.com/security/products/magento/apsb25-94.html)), disclosed in mid-March 2026, that affects **every production version** of Magento Open Source and Adobe Commerce. By the time Sansec found the skimmers, **56% of all vulnerable stores had already been targeted** — within just one week of the vulnerability's disclosure.
And here's the worst part: as of April 12, 2026, **Adobe has not released a production security patch**. The fix exists only in a pre-release alpha build (2.4.9-alpha3+). An estimated **130,000 online stores** running Magento remain vulnerable, representing **$173 billion in annual gross merchandise value**.
:::warning Adobe advisory APSB25-94 covers this vulnerability, but no production patch has been released. If you run Magento, check the Indicators of Compromise listed below immediately.:::
## How Does a 1-Pixel SVG Steal Credit Cards?
This attack is elegant in its simplicity and terrifying in its stealth. Here's exactly how it works, step by step:
### Step 1: The PolyShell Entry
The attacker exploits Magento's REST API file upload functionality. When a product option has type "file," Magento processes an embedded `file_info` object with base64-encoded file data. The uploaded file is a **polyglot** — it functions simultaneously as a valid image AND an executable script.
According to [Searchlight Cyber's analysis](https://slcyber.io/research-center/magento-polyshell-unauthenticated-file-upload-to-rce-in-magento-apsb25-94/), the file is written to `pub/media/custom_options/quote/` on the server, and depending on server configuration, leads to **remote code execution (RCE)** or stored XSS leading to account compromise.
Active exploitation began on **March 19, 2026** — just two days after disclosure. No less than **50 IP addresses** engaged in automated mass scanning ([source](https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/)).
### Step 2: The Invisible SVG
Once inside, the attacker injects a tiny SVG element into the store's HTML:
```xml
```
The entire skimmer payload is **base64-encoded inside an `atob()` call** and executed via `setTimeout`. As [Sansec's researchers](https://sansec.io/research/svg-onload-magecart-skimmer) noted:
> "This technique avoids creating external script references that security scanners typically flag. The entire malware lives inline, encoded as a single string attribute." - Sansec Research
### Step 3: The Fake Checkout
When a buyer clicks checkout, the script intercepts and displays a convincing **"Secure Checkout" overlay** — complete with a lock icon for perceived legitimacy. The form includes credit card fields and billing address, with **real-time Luhn validation** of card numbers. Victims see exactly what they expect to see.
### Step 4: The Exfiltration
Captured payment data is:
1. **XOR-encrypted** with the key `"script"`
2. **Base64-obfuscated** via `btoa()`
3. **Sent via `fetch()` POST** with `no-cors` mode (fallback: hidden iframe; some variants use WebRTC for stealthy exfiltration)
4. **Routed to `/fb_metrics.php`** — disguised as Facebook analytics
**Six exfiltration domains** were identified, all hosted at IP `23.137.249.67` ([IncogNet LLC](https://incognet.io/), AS40663, Netherlands):
| Domain | Confirmed Victims |
|--------|---------|
| statistics-for-you.com | 15 stores |
| statistics-renew.com | 14 stores |
| morningflexpleasure.com | 14 stores |
| reusable-flex.com | 12 stores |
| goingfatter.com | 11 stores |
| wellfacing.com | 10 stores |
A `_mgx_cv` key is set in the browser's localStorage after data capture, preventing duplicate victim submissions. On April 10, [IncogNet confirmed](https://www.bleepingcomputer.com/news/security/hackers-use-pixel-large-svg-trick-to-hide-credit-card-stealer/) they deactivated the offending account — but the underlying Magento vulnerability remains unpatched.
## Why Are SVG Files Dangerous?
This attack exploits a fundamental truth that many designers overlook: **an SVG file is XML, and XML can contain executable code**. Unlike PNG or JPEG, which are pure pixel data, SVGs can include JavaScript, HTML, external resource references, and even entity expansion attacks.

Security researchers at [Fortinet](https://www.fortinet.com/blog/threat-research/scalable-vector-graphics-attack-surface-anatomy) have documented **four primary SVG attack vectors**:
1. **Cross-Site Scripting (XSS)** — SVGs support ECMAScript via `