Formjacking
Malicious code on a real checkout page that copies your card details as you type.
Formjacking is a digital form of card skimming: attackers slip malicious code into the checkout page of an otherwise legitimate website, so that as you enter your card and personal details they are quietly copied and sent to the criminal at the same time as your real order goes through. The danger is that everything looks and works normally — you receive your goods, the site is genuine, and there is nothing on screen to warn you — which is why it can run undetected on a compromised shop for a long time.
It often gets in through a weakness in one of the third-party scripts many sites load, so even careful retailers can be caught out. Because you cannot see it from your side, prevention leans on general good habits: prefer well-known retailers, keep your devices and browser updated, and pay by card so a fraudulent charge can be reversed through chargeback. Watching your statements closely is what catches it, since the first real sign is usually an unfamiliar transaction. It is the checkout-page relative of skimming, and a reminder that even a real site can leak your details.