Hackers Inject Malicious JavaScript Into Okendo Reviews Widget to Target E-Commerce Sites
ID: f0039b91-f2a0-5996-8168-c8034eded0d6
STIX ID: report--f0039b91-f2a0-5996-8168-c8034eded0d6
Feed Name: Cyber Press
A supply-chain attack injected obfuscated JavaScript (attributed to SmartApeSG) into the Okendo Reviews widget used by over 18,000 storefronts. The staged loader uses localStorage-based timing, desktop-only user-agent filtering, and XOR decoding to reconstruct a hidden C2 URL, then deploys ClickFix-style social engineering that tricks victims into running commands which fetch additional downloaders that install NetSupport, Remcos RATs and the StealC stealer. The report provides compromised and malicious URLs and a detection signature for monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
