Plugins on WordPress.org backdoored in supply chain attack
ID: dbfbaf2d-fcc0-50c4-ac96-9a18dec13257
STIX ID: report--dbfbaf2d-fcc0-50c4-ac96-9a18dec13257
Feed Name: Bleeping Computer
Threat Score
A supply-chain compromise on WordPress.org resulted in malicious PHP injections into five plugins that create admin accounts (notably named “Options” and “PluginAuth”), inject SEO spam, and send data to IP 94.156.79.8; the modifications affected plugins installed on over 35,000 sites and most have since received patches after discovery by Wordfence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
