A new type of fraud that alters the Pix QR Code on payment pages of virtual stores has been targeting Brazilian e-commerce sites. The cybersecurity company Kaspersky detected, so far, 90 small and medium-sized online merchants in Brazil infected by a malicious program that replaces the original Pix code with a fraudulent one and diverts the values of these transactions.
The malicious program was recently discovered by independent security researcher known as "eremit4". The fraud has been active since June 2025 and has already affected stores in various segments, such as eyewear, auto parts, fashion, and virtual fundraising platforms.
There is one thing in common among the victims: the use of the open-source Magento e-commerce platform. Cybercriminals use six command and control domains to inject malicious code into checkout pages.
As soon as the customer selects payment via Pix, the code instantly swaps the original QR Code for a fraudulent one, diverting the transaction money to the criminals.




