logo

Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign

ID: fb20a820-93b9-57a4-8306-8ceb5d41c1ae

STIX ID: report--fb20a820-93b9-57a4-8306-8ceb5d41c1ae

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-15

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A threat actor who purchased the Essential Plugin portfolio inserted an unserialize-based RCE backdoor into 30+ widely used WordPress plugins in August 2025; the backdoor stayed dormant until April 2026 when it fetched payloads that injected malicious PHP into wp-config.php and served cloaked SEO spam and redirects (visible only to Googlebot) from a C2 infrastructure that used an Ethereum smart contract for domain resolution. WordPress.org force-pushed updates to disable the plugin phone-home behavior on discovery, but many sites remain persistently infected until wp-config.php is manually cleaned, making this a large-scale supply-chain compromise affecting hundreds of thousands of sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.