Malicious WordPress Plugins with Backdoors Compromise Thousands of Websites
ID: c0240f99-78d4-590f-bd68-7e50c8024cf1
STIX ID: report--c0240f99-78d4-590f-bd68-7e50c8024cf1
Feed Name: TechRepublic Security
Threat Score
A threat actor bought the Essential Plugin portfolio, implanted dormant backdoors into 31 WordPress plugins (including a plugin with ~20k installs), and used an Ethereum smart contract to resolve and persistently update C2 servers; WordPress has removed the plugins and site owners are advised to delete or patch affected plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
