URGENT Magento 2 Malware / Card Skimmer Incident Response – AWS

via Freelancer ·

Budget / Salary€250–750
TypeFreelance project
LocationRemote
Posted1 hour ago
URGENT – Magento 2 Security Incident Response / Malware Forensics / AWS

We require an experienced Magento 2 / Adobe Commerce security specialist for an urgent production incident.

Environment:

Magento 2.4.3-p1
PHP 7.4
AWS EC2
Cloudflare
~30,000 products

We have confirmed malicious JavaScript activity in production, including requests to:

d.digsgogo.com

and evidence of a suspicious checkout form submitting to:

s.setpayto.pw

Checkout has currently been restricted for customer protection.

We need someone who can urgently:

recover/establish secure SSH access through our AWS account if necessary;
preserve forensic evidence before cleanup;
identify the initial compromise and persistence mechanism;
inspect Magento files, generated/static content, database/configuration, cron jobs, Admin/API access and server logs;
identify all malicious files/code/configuration;
clean the environment safely;
rotate/revoke compromised access;
harden Magento/server/Cloudflare;
validate that checkout and storefront are clean before reopening;
investigate recurring OOM/Varnish/PHP/MySQL/Elasticsearch performance incidents;
provide a written technical report with findings, root cause and remediation.

We are not looking for someone who simply deletes infected generated files or runs an antivirus scan. Root-cause and persistence analysis are mandatory.

Please apply only if you have significant Magento 2 security/incident-response experience. Adobe Commerce/Magento certification, AWS experience and previous malware/card-skimmer investigations are strongly preferred.

In your proposal, please provide:

relevant Magento certifications;
examples of similar Magento compromise investigations;
AWS/Linux security experience;
your immediate availability;
your proposed first steps before making any changes to production.
php linux web security magento mysql amazon web services elasticsearch cloudflare incident response security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.