logo

Hackers Abuse Third-Party Okendo Reviews Script to Spread SmartApeSG Malware Campaign

ID: df735280-e3f4-5a2c-9075-67f7fadefc52

STIX ID: report--df735280-e3f4-5a2c-9075-67f7fadefc52

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

Author: Tushar Subhra Dutta

...
...

## Executive summary A supply-chain compromise of the Okendo Reviews third‑party widget (attributed to SmartApeSG) injected a staged JavaScript loader that profiled visitors and pushed PowerShell/HTA payloads via social‑engineering (fake CAPTCHA/ClickFix) to deliver RATs and info‑stealers; Zscaler observed thousands of blocks and reported the incident to Okendo, which cleaned the script.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.