logo

BuddyBoss supply chain attack (Incident)

ID: 83a81554-c453-5938-8c1d-d3dc23e03591

STIX ID: report--83a81554-c453-5938-8c1d-d3dc23e03591

Feed Name: Wiz Cloud Threat Landscape

Threat Score
88/100

Date Published: 2026-03-25

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report documents a full‑spectrum supply‑chain campaign against the BuddyBoss WordPress plugin/theme pipeline: the adversary compromised vendor infrastructure and the update mechanism to distribute trojanized updates that implanted server‑side PHP backdoors. Those backdoors enabled credential and database exfiltration, reverse shells, centralized data collection (including admin credentials and API/payment keys), and persistent remote control across hundreds of affected sites; the actor also leveraged AI assistance to accelerate payload development and operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.