Malware
Web skimmer
Web skimmer is a card-stealing script that runs inside a checkout page in the shopper's browser, rather than on a physical card reader. The store's server may never see the theft.
How it is measured
Check what the checkout page loads and sends. List all scripts, including inline and iframe ones, compare them with the last known-good version, and capture network requests while entering a test card. Extra hosts and unexpected POSTs stand out.
Skimmers may trigger only on the payment page, for real browsers, or when a cart has items. Test with a full cart and a fresh session, and without dev tools open, since some skip when they detect the inspector.
Worked example
A coffee roaster using a hosted checkout with an embedded iframe is told by its processor that 20 cards were reported. On the product page, a script in a 'reviews' widget now makes a request to 'cdn-stars.example', and the widget file's hash changed five days ago.
The widget vendor was breached, so every store using it loaded the code. The roaster removes the widget immediately; the vendor's incident notice arrives two days later with the date range.
How it differs
A skimmer is any code or device that copies card data. A web skimmer is specifically the browser-based kind, delivered by script, often through iframe injection or a third-party tag. A physical skimmer sits on a card reader; the web one needs no hardware on your premises.
Common errors
Believing a hosted payment page makes the whole page safe. Looking only at your own files and not at vendor widgets. Testing with an empty cart. Ignoring the processor's early warning. Removing one script without checking for several.
In practice
Reduce third-party scripts on cart and checkout pages, use SRI for those you keep, and set a CSP that limits connect-src and form-action. Keep a record of each vendor's script and when it changed. If your processor flags cards, scan the checkout first.