All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Large-Scale Supply Chain Attack: 30 WordPress Plugins Purchased and Backdoored

By

speckx

1mo ago· 6 min readenInsight

Summary

The article details a large-scale supply chain attack on WordPress plugins where an individual purchased 30 plugins and systematically planted backdoors in all of them. The attack was discovered when a client reported a security notice about the 'Countdown Timer Ultimate' plugin containing malicious code. The article explains how the attacker acquired legitimate plugins, inserted obfuscated backdoor code, and how security researchers identified and reported the malicious activity. It highlights the growing threat of supply chain attacks in the WordPress ecosystem and provides recommendations for plugin developers and users to protect themselves.

Key quotes

· 5 pulled
A client reported a security notice they found in wp-admin.
The notice was from the WordPress.org Plugins Team, warning that a plugin called Countdown Timer Ultimate contained code that could allow unauthorized third-party access.
This time at a much larger scale.
A trusted name, acquired by a new owner, turned into something malicious.
I ran a full security audit and discovered that the plugin contained obfuscated code that could allow remote code execution.
Snippet from the RSS feed
Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

You might also wanna read