logo

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

ID: 6a74ee4f-931d-588b-a576-142a350b307e

STIX ID: report--6a74ee4f-931d-588b-a576-142a350b307e

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-10

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Unknown actors hijacked Nextend’s update infrastructure to push a trojanized Smart Slider 3 Pro update (v3.5.1.35) that installed a multi-layered backdoor capable of pre-authenticated remote code execution via custom HTTP headers, creating hidden admin accounts, persisting in multiple locations, and exfiltrating site and credential data to wpjs1.com; the malicious build was available for approximately six hours and potentially affected sites that updated during that window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.