Our DNSMon flagged an abnormal domain call magento-analytics[.]com, through continuous tracking, and correlation with various data, we found out that the demesne nominate has been used to inject malicious JS book to various online shopping sites to steal the credit card owner / card number / expiration time / CVV information.