Malware
Formjacking
Formjacking is injected JavaScript that copies what a visitor types into a form, usually checkout, and sends it to the attacker as well as the shop. The order still goes through, so nobody notices.
How it is measured
Watch outbound requests when a form is submitted. A form that posts to your payment provider should not also trigger a request to an unfamiliar domain. Compare the scripts on checkout with a known-good list and look for obfuscated code that attaches `submit` or `input` listeners.
Page-level monitoring tools diff the script inventory of payment pages over time. A new external host on the checkout page deserves a same-day look.
Worked example
A small outdoor-gear store sees a spike in chargebacks over two weeks. A review of the checkout network trace shows a POST to `analytics-collect.cloud-pixel.top` right after each card entry, 612 bytes, with the card number in the body. The script was injected into the theme's `checkout.js`.
The store removes the code, rotates its admin and FTP credentials, and tells its payment processor and customers.
How it differs
Formjacking is the name for the technique of intercepting form fields on the page. Skimmer or Magecart names the groups and tools that do it for card data. A formjacker can also capture login or contact fields, so not all of it is payment theft. Keyloggers capture all keystrokes; formjacking targets form values.
Common errors
Looking only at the server and not the browser. Trusting a PCI scan that only checks the server. Letting a marketing tag manager load scripts onto the payment page. Keeping a stale CDN include. Ignoring chargeback patterns.
In practice
Reduce what runs on checkout: no tag manager, no unneeded widgets, and a tight CSP. Use a payment provider's hosted fields or redirect so card data never touches your page. Alert on any change to scripts loaded on that page.