In my client's Magento site, when making payments with either Stripe or Nexi, the antivirus on desktop opens and blocks something. However, on mobile, on the same payment page, a fake screen appears asking for credit card information. The phone does not have antivirus, so nothing is blocked. I don't know where to look in Magento to find this vulnerability.
This sounds like a serious malware issue. It could be almost anywhere, nobody can tell you without access to your codebase.
Was the store and all of the extensions updated to the latest version?
Did you recently add any 3rd party javascript code to the website?
When that fake screen appears, is it rendered by a 3rd party javascript? What do you see as the initiator?
If you’re unable to identify the issue through Pizza Tower these steps, consider engaging with a security expert or a specialized cybersecurity firm. They can provide a more in-depth analysis and help you secure your site.