logo

Hackers Inject Malicious JavaScript Into Okendo Reviews Widget to Target E-Commerce Sites

ID: f0039b91-f2a0-5996-8168-c8034eded0d6

STIX ID: report--f0039b91-f2a0-5996-8168-c8034eded0d6

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Varshini

...
...

A supply-chain attack injected obfuscated JavaScript (attributed to SmartApeSG) into the Okendo Reviews widget used by over 18,000 storefronts. The staged loader uses localStorage-based timing, desktop-only user-agent filtering, and XOR decoding to reconstruct a hidden C2 URL, then deploys ClickFix-style social engineering that tricks victims into running commands which fetch additional downloaders that install NetSupport, Remcos RATs and the StealC stealer. The report provides compromised and malicious URLs and a detection signature for monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.