Malware
Skimmer
Also called card skimmer.
Skimmer is JavaScript that copies card numbers and other form fields as a shopper types and sends them to the attacker. It lives in the page or in a script the page loads.
How it is measured
Inspect scripts on payment pages. Skimmers listen for submit, blur, or keyup on inputs whose names include card, cc, cvv, or expiry, and send data with an image request, fetch, or WebSocket. Open the network panel, type a test card, and look for any request to a host that is not yours or your processor.
Check where scripts are stored: theme files, a CMS 'header scripts' setting, a tag manager, a stored block in the database, or an image with code appended. Compare against a known-good release and check modification times.
Worked example
A bike shop's checkout page loads 11 scripts. One, /wp-content/uploads/jquery-migrate.min.js, is 1.9 MB when the real file is 14 KB, and its tail holds a base64 string. Decoded, it adds a listener to the billing card field and posts values to 'static-analytix.example/pixel.gif'.
Orders placed with cards from 2 March onward are suspect, based on the file's modification time. The shop sends that date range to its payment provider and clears the upload.
How it differs
Magecart is the label for the groups that run these campaigns; the skimmer is the code they run. You can find a skimmer and have no idea whose it is. Name the file, the host it posts to, and the date it appeared before you attach a group name.
Common errors
Testing checkout with autofill or a card that is not typed. Searching the code for the word skimmer. Removing it but leaving the admin access or plugin hole. Overlooking the payment iframe and checking only the parent. Letting a tag manager container go unreviewed.
In practice
Cut what runs on checkout to a short, justified list, and add CSP connect-src and form-action rules limited to your processor. Alert on changes to checkout templates and script settings. If you find a skimmer, record the dates it was live and tell your payment provider.