logo

The BuddyBoss Attack: Claude’s Supply-Chain Attack

ID: 2658c08c-1fdb-5a0c-a8e8-578a75957ddc

STIX ID: report--2658c08c-1fdb-5a0c-a8e8-578a75957ddc

Feed Name: Ctrl-Alt-Int3l

Threat Score
92/100

Date Published: 2026-04-03

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

This report details a high‑impact supply‑chain attack where a French actor leveraged Anthropic's Claude to backdoor BuddyBoss plugin and theme packages on the Caseproof distribution, bypassed Cloudflare by contacting the Heroku origin, forced updates to clients, and exfiltrated data from 246 WordPress sites (over 16 GB of SQL dumps, ~150k user accounts, and live Stripe API keys); the document analyzes the Claude prompts, attack steps, TTPs, victimology, and C2/exfiltration mechanisms and outlines remediation complexity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.