SmartApeSG Hackers Abuse Okendo Reviews Widget in E-Commerce Supply Chain Attack
ID: 82e3a831-7d39-58fe-aac5-cfb347a022d9
STIX ID: report--82e3a831-7d39-58fe-aac5-cfb347a022d9
Feed Name: GBHackers
## Executive Summary — The Okendo Reviews widget was compromised by the SmartApeSG threat actor, who injected an obfuscated staged JavaScript loader into the vendor’s widget deployed across thousands of e-commerce sites; the loader performs environment checks, runtime deobfuscation, and dynamic script retrieval to deliver follow-on social-engineered prompts that can lead to PowerShell/HTA downloaders and deployment of RATs and info-stealers. Zscaler ThreatLabz observed a large detection spike (nearly 15,000 blocks on May 14, 2026) and the report includes IOCs and defensive recommendations such as SRI/CSP, integrity monitoring, and behavioral detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
