<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj" -->

---
title: Malicious AI agents steal 600K credit cards, infect 100+...
description: A financially motivated threat actor is using open-source AI agent frameworks—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes...
canonical: https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers | daily.dev
og:description: A financially motivated threat actor is using open-source AI agent frameworks—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes...
og:url: https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj
og:image: https://api.daily.dev/og/posts/zgB8oXEhJ.png
og:image:alt: Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 14 upvotes · 2 comments

## Summary

A financially motivated threat actor is using open-source AI agent frameworks—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes (powered by Claude Opus 4.6) for orchestration—to attack online retailers at scale. Active since at least July, the campaign has compromised at least 119 websites, stolen over 600,000 credit card records, and breached major organizations including a Fortune 500 hospitality company and a major U.S. airline. Skimmers were injected via multiple techniques including JavaScript poisoning, malicious script tags, S3/CDN poisoning, and Kubernetes deployment changes. Cybersecurity startup Gambit found the campaign costs roughly $25 per targeted company, and attackers even ran cleanup routines to wipe extracted card data from Magento databases, sometimes causing operational disruptions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers>

## Questions this post answers

### How are attackers using AI agents to steal credit card data from online stores?

A threat actor chains three open-source AI agent tools—Strix for vulnerability scanning, Cairn for autonomous exploitation to gain shell or admin access, and Hermes for orchestration using claude-opus-4.6—to compromise retailer websites and deploy skimmer malware. Since July, the campaign has hit at least 119 sites and stolen over 600,000 credit card records, often requiring only hours of automated work per target after brief human instructions.

_Security teams tracking AI-driven attack techniques can follow developments like this on daily.dev._

### How much does it cost attackers to run an AI-powered skimmer attack against a company?

Running an AI agent-driven skimmer attack costs roughly $25 per targeted company on average. Cybersecurity researchers found an OpenRouter account spent $7,005.71 over about four weeks, with total campaign costs estimated between $12,000 and $18,000; the attacker's own records show costs ranging from $3.13 to $79.31 per completed scan across 101 targets.

_Anyone budgeting defenses against automated attacks can track these cost figures on daily.dev._

### What methods are used to inject credit card skimmer malware onto compromised websites?

Observed skimmer injection methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to automatically restore the skimmer after removal attempts.

_Teams hardening checkout pages against skimmers can keep up with attacker techniques via daily.dev._

## Community discussion

Top comments from developers on daily.dev.

**@orifjonisroilov** · 0 upvotes

> Orifjon

**@andradei** · 0 upvotes

> Dumb image. But yeah.. AI accelerate both solutions and problems. We are the bottleneck now in this race...

## Similar posts on daily.dev

- [Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages](https://daily.dev/posts/long-running-web-skimming-campaign-steals-credit-cards-from-online-checkout-pages-kaszv4xrt) · The Hacker News · 0 upvotes · 0 comments
- [Credit card theft campaign abuses Stripe to host stolen payment info](https://daily.dev/posts/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info-bxtmvtzh5) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#webdev](https://daily.dev/tags/webdev), [#ai-agents](https://daily.dev/tags/ai-agents), [#malware](https://daily.dev/tags/malware), [#claude](https://daily.dev/tags/claude)

[View this post on daily.dev](https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers","url":"https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj"},"datePublished":"2026-09-23T16:23:29.189Z","dateModified":"2026-09-23T18:11:04.863Z","description":"A financially motivated threat actor is using open-source AI agent frameworks—Strix for vulnerability scanning, Cairn for autonomous exploitation, and Hermes...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b760a1b3d5ee6386e4569a4e608a6e00?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b760a1b3d5ee6386e4569a4e608a6e00?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":2,"discussionUrl":"https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":14},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":2}],"keywords":"webdev,ai-agents,malware,claude","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj","comment":[{"@type":"Comment","text":"Orifjon","datePublished":"2026-09-24T13:40:43.636Z","url":"https://daily.dev/posts/zgB8oXEhJ#c-1wQTaINWs","author":{"@type":"Person","name":"Orifjon Isroilov","url":"https://daily.dev/orifjonisroilov","image":"https://lh3.googleusercontent.com/a/ACg8ocI0JaxqAXn17bBkOc4sRYzBcO8HTIggZMoYZ7e4_KCPTIzACQ=s96-c"}},{"@type":"Comment","text":"Dumb image. But yeah… AI accelerate both solutions and problems. We are the bottleneck now in this race…","datePublished":"2026-09-24T20:52:41.414Z","url":"https://daily.dev/posts/zgB8oXEhJ#c-SQV3tIymH","author":{"@type":"Person","name":"Isaac de Andrade","url":"https://daily.dev/andradei","image":"https://avatars.githubusercontent.com/u/2653546?v=4"}}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/malicious-ai-agents-steal-600k-credit-cards-infect-100-sites-with-skimmers-zgb8oxehj#faq","mainEntity":[{"@type":"Question","name":"How are attackers using AI agents to steal credit card data from online stores?","acceptedAnswer":{"@type":"Answer","text":"A threat actor chains three open-source AI agent tools—Strix for vulnerability scanning, Cairn for autonomous exploitation to gain shell or admin access, and Hermes for orchestration using claude-opus-4.6—to compromise retailer websites and deploy skimmer malware. Since July, the campaign has hit at least 119 sites and stolen over 600,000 credit card records, often requiring only hours of automated work per target after brief human instructions. Security teams tracking AI-driven attack techniques can follow developments like this on daily.dev."}},{"@type":"Question","name":"How much does it cost attackers to run an AI-powered skimmer attack against a company?","acceptedAnswer":{"@type":"Answer","text":"Running an AI agent-driven skimmer attack costs roughly $25 per targeted company on average. Cybersecurity researchers found an OpenRouter account spent $7,005.71 over about four weeks, with total campaign costs estimated between $12,000 and $18,000; the attacker's own records show costs ranging from $3.13 to $79.31 per completed scan across 101 targets. Anyone budgeting defenses against automated attacks can track these cost figures on daily.dev."}},{"@type":"Question","name":"What methods are used to inject credit card skimmer malware onto compromised websites?","acceptedAnswer":{"@type":"Answer","text":"Observed skimmer injection methods include appending malicious code to legitimate JavaScript files, adding script tags to checkout pages or Google tag blocks, poisoning S3/CDN content and server-side caches, modifying database fields, altering Kubernetes deployments, and using cron jobs to automatically restore the skimmer after removal attempts. Teams hardening checkout pages against skimmers can keep up with attacker techniques via daily.dev."}}]}
```

