Hackers Hide Backdoor in Trusted WordPress Plugins for 8 Months Before Activating Malware
ID: 028ddeb5-948b-5f3a-ac90-e006efd3f84e
STIX ID: report--028ddeb5-948b-5f3a-ac90-e006efd3f84e
Feed Name: cybersecurityNews.com
A buyer acquired the 'Essential Plugin' WordPress plugin portfolio and, beginning with the first commit, introduced a PHP deserialization backdoor in a plugin update (Aug 2025) and injected persistent malicious code into wp-config.php that remained inactive until April 2026. When activated the compromise delivered hidden spam, fake pages, and redirects served only to Googlebot, affecting 31 plugins and hundreds of thousands of sites; WordPress.org removed the plugins but did not remediate wp-config.php infections. The attacker used an Ethereum smart contract to resolve and update command-and-control infrastructure, complicating takedown efforts; site owners must inspect wp-config.php and remove infected installations, and WordPress.org should adopt ownership-transfer review processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
