logo

The BuddyBoss Attack: Full Incident Analysis

ID: 8d45207c-c2bf-5be0-93af-a0bef512abaa

STIX ID: report--8d45207c-c2bf-5be0-93af-a0bef512abaa

Feed Name: Ctrl-Alt-Int3l

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-04-19

Author: Ctrl-Alt-Intel

...
...

This report documents a fast, automated supply-chain attack in which a malicious GitHub Actions workflow committed to BuddyBoss repositories exfiltrated CI/CD secrets, enabling SSH and AWS access, root escalation, and the upload of backdoored plugin/theme packages to the Caseproof Mothership CDN; the injected backdoors auto-exfiltrated site credentials and provided interactive remote control, leading to callbacks from 246+ WordPress sites and theft of sensitive data such as Stripe keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.