URGENT Magento 2 Malware / Card Skimmer Incident Response – AWS
Budget / Salary€250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
URGENT – Magento 2 Security Incident Response / Malware Forensics / AWS
We require an experienced Magento 2 / Adobe Commerce security specialist for an urgent production incident.
Environment:
Magento 2.4.3-p1
PHP 7.4
AWS EC2
Cloudflare
~30,000 products
We have confirmed malicious JavaScript activity in production, including requests to:
d.digsgogo.com
and evidence of a suspicious checkout form submitting to:
s.setpayto.pw
Checkout has currently been restricted for customer protection.
We need someone who can urgently:
recover/establish secure SSH access through our AWS account if necessary;
preserve forensic evidence before cleanup;
identify the initial compromise and persistence mechanism;
inspect Magento files, generated/static content, database/configuration, cron jobs, Admin/API access and server logs;
identify all malicious files/code/configuration;
clean the environment safely;
rotate/revoke compromised access;
harden Magento/server/Cloudflare;
validate that checkout and storefront are clean before reopening;
investigate recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents;
provide a written technical report with findings, root cause and remediation.
We are not looking for someone who simply deletes infected generated files or runs an antivirus scan. Root-cause and persistence analysis are mandatory.
Please apply only if you have significant Magento 2 security/incident-response experience. Adobe Commerce/Magento certification, AWS experience and previous malware/card-skimmer investigations are strongly preferred.
In your proposal, please provide:
relevant Magento certifications;
examples of similar Magento compromise investigations;
AWS/Linux security experience;
your immediate availability;
your proposed first steps before making any changes to production.
We require an experienced Magento 2 / Adobe Commerce security specialist for an urgent production incident.
Environment:
Magento 2.4.3-p1
PHP 7.4
AWS EC2
Cloudflare
~30,000 products
We have confirmed malicious JavaScript activity in production, including requests to:
d.digsgogo.com
and evidence of a suspicious checkout form submitting to:
s.setpayto.pw
Checkout has currently been restricted for customer protection.
We need someone who can urgently:
recover/establish secure SSH access through our AWS account if necessary;
preserve forensic evidence before cleanup;
identify the initial compromise and persistence mechanism;
inspect Magento files, generated/static content, database/configuration, cron jobs, Admin/API access and server logs;
identify all malicious files/code/configuration;
clean the environment safely;
rotate/revoke compromised access;
harden Magento/server/Cloudflare;
validate that checkout and storefront are clean before reopening;
investigate recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents;
provide a written technical report with findings, root cause and remediation.
We are not looking for someone who simply deletes infected generated files or runs an antivirus scan. Root-cause and persistence analysis are mandatory.
Please apply only if you have significant Magento 2 security/incident-response experience. Adobe Commerce/Magento certification, AWS experience and previous malware/card-skimmer investigations are strongly preferred.
In your proposal, please provide:
relevant Magento certifications;
examples of similar Magento compromise investigations;
AWS/Linux security experience;
your immediate availability;
your proposed first steps before making any changes to production.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.