Keyloggers Injected in Web Trust Seal Supply Chain Attack
Hackers compromised the script used by Best of the Web to display their trust seal on their customers’ websites and to add two key logging scripts designed to sniff keystrokes from visitors. After de Groot disclosed his discovery to Best of the Web, the company confirmed that their trust seal script which was hosted on Amazon’s content delivery network (CDN) was indeed hacked. As Best of the Web Trust Seal Team said in an email to BleepingComputer:
Earlier today, we were notified that the script we use to display trust seals that we host on Amazon’s content delivery network (CDN) was compromised.
Source: www.bleepingcomputer.com