Hackers Compromised ILSpy WordPress Domain to Deliver Malware
ID: f8936562-638e-5e8e-9e86-74e6a97088c4
STIX ID: report--f8936562-638e-5e8e-9e86-74e6a97088c4
Feed Name: cybersecurityNews.com
A supply-chain attack compromised the official ILSpy WordPress site on April 6, 2026: download links were altered to redirect visitors to a malicious page that prompted installation of a browser extension delivering spyware capable of stealing session cookies, passwords, and developer credentials. An independent researcher captured the activity, the compromised site was taken offline (returning 502), and security teams are analyzing the extension to extract IoCs; developers are advised to verify final URLs, avoid unexpected extensions, and download tools from verified repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
