Once the app finds a matching device, it tries to connect with the default password of 1234.

Finally, the app sends the letter 'P' to the device, and if the device responds with 'M', there's probably a card skimmer nearby.

The letter 'P' is one of several commands that Spark Fun identified, which always returns 'M' with the tested skimmers (I assume it's a debugging command).

You can download the app from the Play Store below, and the code is open-source too.

Generally speaking, a skimmer is a small device used to steal credit/debit card information.

Thieves will place them on top of card insertion slots on unwatched payment terminals (example), like those on gas station pumps and outdoor ATMs.

