URGENT Magento 2 Malware / Card Skimmer Incident Response – AWS
Employer not named by the sourceRemote
Frontier is not the employer and does not collect applications.
About this role
PHP, Linux, Web Security, Magento, MySQL, Amazon Web Services, Elasticsearch, Cloudflare, Incident Response, Security Auditing · URGENT – Magento 2 Security Incident Response / Malware Forensics / AWS
We require an experienced Magento 2 / Adobe Commerce security specialist for an urgent production incident.
Environment:
Magento 2.4.3-p1 PHP 7.4 AWS EC2 Cloudflare ~30,000 products
We have confirmed malicious JavaScript activity in production, including requests to:
d.digsgogo.com
and evidence of a suspicious checkout form submitting to:
s.setpayto.pw
Checkout has currently been restricted for customer protection.
We need someone who can urgently:
recover/establish secure SSH access through our AWS account if necessary; preserve forensic evidence before cleanup; identify the initial compromise and persistence mechanism; inspect Magento files, generated/static content, database/configuration, cron jobs, Admin/API access and server logs; identify all malicious files/code/configuration; clean the environment safely; rotate/revoke compromised access; harden Magento/server/Cloudflare; validate that checkout and storefront are clean before reopening; investigate recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents; provide a written technical report with findings, root cause and remediation.