logo

Uncanny Automator Breach: Backdoored Plugin Build Hit WordPress Sites

ID: 7d57191e-dbe2-5e68-9201-4909a26f41bc

STIX ID: report--7d57191e-dbe2-5e68-9201-4909a26f41bc

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-06-15

Date Updated: 2026-06-15

Author: Do Son

...
...

Uncanny Automator’s update infrastructure was compromised on June 12, 2026: attackers swapped the Pro plugin update for a backdoored build (v7.3.0.5) that delivered malware/backdoors to sites checking for updates and also accessed the licensing database, exposing names, emails, license keys and site URLs. The tampered build affected fewer than 6% of sites over ~21 hours; Uncanny Owl removed attacker access, released a clean 7.3.0.6, reset passwords, and cleaned infrastructure, but infected sites require full remediation and leaked contact data raises phishing risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.