Shellback SEO
Security Case Study

Your Shopify checkout is redirecting to "TrendPay." That's a card skimmer.

A live Shopify store was silently sending shoppers to a fake "TrendPay" credit-card page at checkout. Here's what it really was, why backups couldn't fix it, and exactly how we shut it down — end to end.

Threat: Card-skimming redirectOutcome: Removed & verified
!

If you're seeing this on your own store, stop taking orders through it.

Do not let anyone enter a card on that "TrendPay" page. It is not a payment provider — it's a criminal page harvesting card numbers.

What "TrendPay" actually is

"TrendPay" is a fake, look-alike checkout used to steal card data — the technique the security world calls digital skimming or Magecart. When a customer clicks Check Out, hidden code hijacks the button and sends the browser to an attacker-controlled page that clones your real cart and totals so it looks legitimate, shows a convincing credit-card form, and sends whatever the shopper types straight to the criminal.

The pages live on throwaway domains that rotate constantly — we watched checjk.googlecheck.top switch to checjk.paytrend.top mid-investigation — and the kit is reused across many victim stores. The one we found still carried leftover template text from a completely unrelated shop.

Why it's so dangerous — and so hard to find

Server-side

Served by the store itself, so it hit every visitor on every device — phone, tablet, desktop.

Not in the theme

Nothing in the theme files or settings — which is exactly why restoring backups did nothing.

Hidden in an app

Delivered through a trusted, years-old cart app whose settings had been weaponized.

Obfuscated

A 42 KB scrambled script that decoded the criminal domain at runtime and blended in by design.

On the surface, everything looked normal. The redirect only fired the moment someone actually clicked the checkout button — which is what makes these so easy to miss and so costly to ignore.

How we tracked it down

  1. Ruled out the innocent explanations

    Confirmed payment settings, theme code, URL redirects, and tracking pixels were all clean.

  2. Reproduced the attack

    Clicked the live checkout and captured the exact redirect to the criminal "TrendPay" domain.

  3. Proved it was server-side

    Reproduced it on a clean browser — ruling out device malware and pointing inside the store.

  4. Isolated the payload

    Found the obfuscated script and confirmed it wasn't in any theme file.

  5. Traced it to the source

    Pinpointed the exact app-embed block delivering the skimmer.

How to remove it

  1. Disable the malicious app embed

    Online Store → Themes → Customize → App embeds. This immediately stops the redirect for shoppers.

  2. Verify the fix

    On the live cart, confirm the injected script is gone and Check Out lands on your genuine Shopify checkout (yourstore.com/checkouts/…).

  3. Uninstall the compromised app

    So it can't be switched back on or re-inject elsewhere. Watch for it trying to escalate permissions on the way out — the one we removed suddenly demanded access to edit discounts. Deny it.

  4. Re-verify end to end

    Add to cart, check out, and confirm a clean, native Shopify checkout every time.

Check your own store in 30 seconds

Add a product, open your cart, and click Check Out while watching the address bar. If it ever leaves your own domain — a .top address, a "pay"-branded page you don't recognize — you have a skimmer. Don't process another order through it.

Think your Shopify store might be compromised?

This is exactly what we do. Shellback SEO found, traced, and removed this skimmer end to end — and we can check or clean your store too.

Get a free store check →

Prepared by Shellback SEO — Shopify security response & remediation. Client details redacted.

shellback seo Promo Codes