Pedro Fortuna

Explore articles by Pedro

Products & Platform

Security Incident Postmortem: Malicious Versions of the jscrambler npm Package

On 11 July 2026, an attacker published several malicious versions of our public jscrambler npm package, the command-line tool used with our Code Integrity product. The attacker had gained write…

Read more
Software Supply Chain Security

OWASP’s Biggest Signal in Years: Supply Chain Is Now a Top-3 Risk — And It Includes the Client Side

When OWASP surveyed 225 security practitioners for the 2025 Top 10 update, something unusual happened. Software Supply Chain Failures didn’t just make the list — it received 106 first-place votes…

Read more
Compliance Enforcement

Jscrambler Launches First AI-Assistant for PCI DSS Script Authorization Workflows

Today marks one of the most essential milestones in Jscrambler’s history — and in the evolution of client-side security.We’re proud to announce that the Jscrambler PCI DSS Solution is the…

Read more
Compliance Enforcement

Navigating PCI DSS v4 Compliance: The CSP/SRI-Based Approach

Originally posted in January 2025In light of the upcoming PCI DSS future-dated requirements deadline (March 31st, 2025), many companies are evaluating tools and solutions to help them comply with the…

Read more
Security Research

The npm chalk and debug attack proves again: the web’s trust model is broken

On September 8th, 2025, Aikido reported a major supply chain attack affecting dozens of npm packages, including the hugely popular chalk and debug. In total, the compromised packages represent 2.6…

Read more
Security Research

Charity Hacked: Web Skimmer Infected Caritas Spain Websites for Over a Year

with David Alves and Pedro MarruchoThis research documents Jscrambler’s investigation into a stealthy web skimming campaign that infiltrated multiple Caritas Spain websites of Caritas Internationalis, a confederation of over 160…

Read more
Security Research

Stripe API Skimming Campaign: Additional Victims and Insights

with David Alves and Pedro MarruchoResearch Update 4/4/25 — Given some misrepresentations of the research described below, Jscrambler clarifies that it has not found any security issues with Stripe’s API…

Read more
Products & Platform

Introducing Iframe Integrity: Redefining Payment Page Security for PSPs

At Jscrambler, innovation often starts with a simple conversation, and the story of our latest product, Iframe Integrity, is no different.It was October 2023, and I was attending the PCI…

Read more
Security Research

Stealing Seconds: Web Skimmer Compromises Casio UK and Growing Number of Websites

with David Alves and Pedro MarruchoWe just uncovered a new batch of web skimmer infections affecting multiple websites, including casio.co.uk. So far, we have confirmed 17 victim websites, though this…

Read more
Compliance Enforcement

The New Changes to SAQ A

The PCI SSC announced a new Self-assessment Questionnaire A (SAQ A) version today. This update removes the new requirements introduced in PCI DSS v4 designed to combat e-skimming attacks (6.4.3…

Read more
Client-Side Security

The Mongolian Skimmer: different vests, all equally dangerous

with Pedro Marrucho and David AlvesA few weeks ago, while consulting skimming threat intel sources Jscrambler researchers stumbled across a new skimming campaign that, at first glance, stood out because…

Read more
Client-Side Security

Reflecting on the CrowdStrike Incident: It’s Not Them, It’s Us

This article was originally published on LinkedIn, on July 20th 2024. It’s been updated and reposted here, having incorporated information from the RCA report that was released by CrowdStrike.The now…

Read more
Client-Side Security

Starting OWASP Lisboa: Giving back to the community

Starting OSWASP Lisboa, Portugal, is about giving back to the community. It has been almost twelve years since I first attended an OWASP event, the OWASP Summit 2011 in Portugal,…

Read more
Client-Side Security

CSP & Magecart Web Skimmers: Facts and Fiction

What are the facts and the fiction behind Content Security Policy (CSP) and Magecart web skimmers?With e-commerce displaying no signs of slowing down since the start of the COVID-19 pandemic,…

Read more
Client-Side Security

How to Protect Your Source Code With GitLab and Jscrambler

In this tutorial, we explore the importance of protecting client-side application code at runtime and guide you through implementing it in your GitLab instance using the integration with Jscrambler.Development teams…

Read more
Client-Side Security

How Your Code Dependencies Expose You To Web Supply Chain Attacks

We will walk you through the risks of code dependencies when it comes to web supply chain attacks.As the demand for faster product development continues to grow, developers increasingly rely…

Read more
Client-Side Security

Insights From a Crypto Wallet Phishing Attack

Today, we give you insights from a Crypto Wallet Phishing Attack.How did scammers use the source code to perpetrate a phishing attack against the cryptocurrency wallet Celsius?Celsius Email System BreachIn…

Read more
Client-Side Security

Memory Protection: An Extra Line of Defense Against Spectre Attacks

Memory protection is an extra line of defense against Spectre attacks. In this blog article, we explore why development teams need to deploy application-level mitigation measures.Even five years after the…

Read more
Client-Side Security

Source Code Protection in Hybrid Mobile Apps

Hybrid mobile apps have become business assets. Perhaps you’ve heard the phrase “every company is an app company” before.Mobile apps have effectively transformed whole industries like transportation, media, retail, and…

Read more
Client-Side Security

12 Checklist Items for Defeating Magecart Attacks

Magecart groups have made many successful attacks on high-profile companies over the past years.In a Magecart attack, attackers covertly inject credit card skimming code into the checkout pages of e-commerce…

Read more
Client-Side Security

Closing Security Gaps in Mobile Apps With Source Code Protection

Close security gaps. Stay ahead of attackers and cybercriminals with source code protection.The Department of Justice and the Federal Trade Commission have been issuing more scam alerts since the pandemic…

Read more
Client-Side Security

How To Protect Your Organization From Magecart

The cybersecurity attacks on the likes of British Airways, Macy’s, and Forbes, amongst others, have been widely reported.They all had in common the fact that they were targeted by Magecart.…

Read more
Client-Side Security

3 Main Steps to Prevent Magecart Attacks

Prevent Magecart refers to overcoming possible cyberattacks involving digital credit card theft by skimming online payment forms.Gaining mainstream media attention over the last year or so, their most recent high-profile…

Read more
Client-Side Security

Is the Enterprise on the Brink of a Global Web Supply Chain Attack?

Web supply chain attacks are a real security threat for which the enterprise is vastly unprepared.The security threats of relying on third-party code are mostly known within the scope of…

Read more
Client-Side Security

Magecart Victim? You Won’t Even Know Unless You Do This

If someone at your company were to tell you that a critical database was left unprotected for the past six months, exposing the data of millions of your customers, you’d…

Read more
Client-Side Security

Open Source Components and a Push for In-Depth Security

The recent incident with the event-stream JavaScript library has several people questioning the security of using open-source components. By falling under (legitimate) control of a developer with malicious intents, the…

Read more
Client-Side Security

ICO Case Study | Tackling Cryptojacking with Real-time Webpage Monitoring

This weekend, the UK’s Information Commissioner’s Office website – ICO was caught serving the CoinHive crypto miner to its users. CoinHive crypto miner is a JavaScript that can be installed…

Read more
Client-Side Security

Is Neglecting the Client Side Costing Your Business?

“Companies of all shapes and sizes rely on a webpage that anchors them to the online world.Webpages represent the face of the majority of businesses and provide a first glimpse…

Read more
Client-Side Security

How Secure is your Web Browser?

“JavaScript is ubiquitous. Everywhere you look, something has been created, at least in part, using JavaScript. JavaScript is so easy to learn and use, as there is a wide availability…

Read more
Client-Side Security

Jscrambler 4.0 is Here!

We have released our latest version, Jscrambler 4.0!It is a breakthrough for JavaScript Security. You will notice many improvements, from our interface to our transformations, to ensure the integrity of…

Read more
Client-Side Security

Migrating your Gitlab Infrastructure into Docker

Bring your GitLab down to see how quickly you can annoy your developers. If you did that already, you know how sensitive your built environment is, and you should do…

Read more
Client-Side Security

We’re Now AppSec Official Supporters

If you work in AppSec, you already know about the paramount importance of the work being developed by the OWASP. Through the years we have benefited in countless ways, through…

Read more
Client-Side Security

Full-stack JavaScript Source Code Protection

Good news for the Node.js aficionados! Jscrambler now officially supports protecting the source of Node.js apps. If you have been paying attention, Node.js has undoubtedly risen.Perhaps you are already using…

Read more