WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce Sites

Mar 26, 2026

Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and exfiltrate data, effectively bypassing security controls.
“Instead of the usual HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec said in a report published this week.
The attack,

Get Free Report & Network Analysis

Please check your email for the free report.