A new Magecart campaign exploits Stripe's API infrastructure and Google Tag Manager to deliver and exfiltrate stolen payment card data from e-commerce checkout pages. The skimmer loads via a legitimate-looking GTM container, reads JavaScript payload from a Stripe customer record's metadata fields, captures payment details (card number, CVV, expiry, billing info), and stores stolen data as fake Stripe customer objects — effectively using Stripe as a covert data exfiltration backend. Because api.stripe.com is trusted by default in Content Security Policy rules, the attack bypasses typical network filters. A variant using Google Firestore instead of Stripe was also discovered. The campaign appears to have been active since at least December 24, 2025, targeting Magento/Adobe Commerce stores.