Malware
Keylogger
Keylogger is malware that records what someone types and sends it to the attacker. It can sit in the operating system or in a web page's JavaScript.
How it is measured
On a computer, look for a process that hooks keyboard events or reads input devices, writes a log file, or uploads small text bursts regularly. On a website, look for scripts that add `keydown`, `keypress`, or `input` listeners and send data to another host.
Open dev tools on a login page and check the network tab while typing. A request that fires on each few keystrokes, or at submit, to a host that is not yours is the sign.
Worked example
A user complains that a hotel booking site is slow on the payment step. Inspecting the page, a script from `static-forms.cdn-lite.top` adds an `input` listener to every field and batches values into a POST every 5 seconds. The request body carries the cardholder name as it is typed, before the form is even submitted.
The owner traces the script to a tag manager container edited by a former contractor, removes it, and revokes that contractor's account.
How it differs
A keylogger records keystrokes continuously. An infostealer grabs stored data in one pass. A browser-side keylogger overlaps with formjacking, which targets form values specifically. A hardware keylogger is a physical device that sits between keyboard and computer, and it has no software footprint at all.
Common errors
Believing virtual keyboards defeat all of them. Looking only at the submit request. Overlooking tag managers. Cleaning a desktop machine and keeping the same passwords. Assuming a password manager is useless against this when autofill avoids typing.
In practice
Use a password manager's autofill, which avoids keystrokes, and a second factor that cannot be typed into a page, such as a hardware key. On your site, audit scripts on login and payment pages and keep tag manager access small.