# Hackers Are Hiding Malware in 1-Pixel SVGs — What Every Designer Needs to Know About SVG Security in 2026 > A 1×1 pixel SVG just stole credit card data from 99 e-commerce stores. SVG-based attacks are up 50x since 2024. Here's how the attack works, why Adobe still hasn't patched it, and how to protect yourself. **Source:** https://vectosolve.com/blog/svg-security-polyshell-malware-designers-2026 **Author:** Robin Monteiro (Founder of VectoSolve) **Published:** 2026-04-12 **Category:** Technology **Reading time:** 12 min read **Tags:** svg security, svg malware, polyshell, magento hack, credit card skimmer, xss, svg sanitization, web security, magecart, e-commerce security --- ## A Single Pixel Stole Millions in Credit Card Data On April 7, 2026, security researchers at [Sansec](https://sansec.io/research/svg-onload-magecart-skimmer) discovered something chilling: **99 Magento e-commerce stores** had been silently compromised by a credit card skimmer hidden inside a **1×1 pixel SVG element**. The entire malware payload — the fake checkout form, the data encryption, the exfiltration logic — was encoded in a single `onload` attribute. No external scripts. No suspicious network requests to flag. Just one invisible pixel, quietly stealing every credit card number entered on the checkout page. The entry point? A vulnerability called **PolyShell** ([APSB25-94](https://helpx.adobe.com/security/products/magento/apsb25-94.html)), disclosed in mid-March 2026, that affects **every production version** of Magento Open Source and Adobe Commerce. By the time Sansec found the skimmers, **56% of all vulnerable stores had already been targeted** — within just one week of the vulnerability's disclosure. And here's the worst part: as of April 12, 2026, **Adobe has not released a production security patch**. The fix exists only in a pre-release alpha build (2.4.9-alpha3+). An estimated **130,000 online stores** running Magento remain vulnerable, representing **$173 billion in annual gross merchandise value**. :::warning Adobe advisory APSB25-94 covers this vulnerability, but no production patch has been released. If you run Magento, check the Indicators of Compromise listed below immediately.::: ## How Does a 1-Pixel SVG Steal Credit Cards? This attack is elegant in its simplicity and terrifying in its stealth. Here's exactly how it works, step by step: ### Step 1: The PolyShell Entry The attacker exploits Magento's REST API file upload functionality. When a product option has type "file," Magento processes an embedded `file_info` object with base64-encoded file data. The uploaded file is a **polyglot** — it functions simultaneously as a valid image AND an executable script. According to [Searchlight Cyber's analysis](https://slcyber.io/research-center/magento-polyshell-unauthenticated-file-upload-to-rce-in-magento-apsb25-94/), the file is written to `pub/media/custom_options/quote/` on the server, and depending on server configuration, leads to **remote code execution (RCE)** or stored XSS leading to account compromise. Active exploitation began on **March 19, 2026** — just two days after disclosure. No less than **50 IP addresses** engaged in automated mass scanning ([source](https://www.bleepingcomputer.com/news/security/new-polyshell-flaw-allows-unauthenticated-rce-on-magento-e-stores/)). ### Step 2: The Invisible SVG Once inside, the attacker injects a tiny SVG element into the store's HTML: ```xml ``` The entire skimmer payload is **base64-encoded inside an `atob()` call** and executed via `setTimeout`. As [Sansec's researchers](https://sansec.io/research/svg-onload-magecart-skimmer) noted: > "This technique avoids creating external script references that security scanners typically flag. The entire malware lives inline, encoded as a single string attribute." - Sansec Research ### Step 3: The Fake Checkout When a buyer clicks checkout, the script intercepts and displays a convincing **"Secure Checkout" overlay** — complete with a lock icon for perceived legitimacy. The form includes credit card fields and billing address, with **real-time Luhn validation** of card numbers. Victims see exactly what they expect to see. ### Step 4: The Exfiltration Captured payment data is: 1. **XOR-encrypted** with the key `"script"` 2. **Base64-obfuscated** via `btoa()` 3. **Sent via `fetch()` POST** with `no-cors` mode (fallback: hidden iframe; some variants use WebRTC for stealthy exfiltration) 4. **Routed to `/fb_metrics.php`** — disguised as Facebook analytics **Six exfiltration domains** were identified, all hosted at IP `23.137.249.67` ([IncogNet LLC](https://incognet.io/), AS40663, Netherlands): | Domain | Confirmed Victims | |--------|---------| | statistics-for-you.com | 15 stores | | statistics-renew.com | 14 stores | | morningflexpleasure.com | 14 stores | | reusable-flex.com | 12 stores | | goingfatter.com | 11 stores | | wellfacing.com | 10 stores | A `_mgx_cv` key is set in the browser's localStorage after data capture, preventing duplicate victim submissions. On April 10, [IncogNet confirmed](https://www.bleepingcomputer.com/news/security/hackers-use-pixel-large-svg-trick-to-hide-credit-card-stealer/) they deactivated the offending account — but the underlying Magento vulnerability remains unpatched. ## Why Are SVG Files Dangerous? This attack exploits a fundamental truth that many designers overlook: **an SVG file is XML, and XML can contain executable code**. Unlike PNG or JPEG, which are pure pixel data, SVGs can include JavaScript, HTML, external resource references, and even entity expansion attacks. ![SVG security — sanitization shield blocking malicious scripts while allowing clean vector paths](/articles-nouveau/polyshell-svg-security.png "SVGs can contain JavaScript, event handlers, and external references — sanitization is critical") Security researchers at [Fortinet](https://www.fortinet.com/blog/threat-research/scalable-vector-graphics-attack-surface-anatomy) have documented **four primary SVG attack vectors**: 1. **Cross-Site Scripting (XSS)** — SVGs support ECMAScript via `