Large-Scale Supply Chain Attack: 30 WordPress Plugins Purchased and Backdoored
By
speckx
Slow-proofed and worth the wait. Worth its weight in flour.
Summary
The article details a large-scale supply chain attack on WordPress plugins where an individual purchased 30 plugins and systematically planted backdoors in all of them. The attack was discovered when a client reported a security notice about the 'Countdown Timer Ultimate' plugin containing malicious code. The article explains how the attacker acquired legitimate plugins, inserted obfuscated backdoor code, and how security researchers identified and reported the malicious activity. It highlights the growing threat of supply chain attacks in the WordPress ecosystem and provides recommendations for plugin developers and users to protect themselves.
Key quotes
· 5 pulledA client reported a security notice they found in wp-admin.
The notice was from the WordPress.org Plugins Team, warning that a plugin called Countdown Timer Ultimate contained code that could allow unauthorized third-party access.
This time at a much larger scale.
A trusted name, acquired by a new owner, turned into something malicious.
I ran a full security audit and discovered that the plugin contained obfuscated code that could allow remote code execution.
You might also wanna read

What to do when one of your WordPress plugins gets compromised
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

Understanding and Preventing WordPress SQL Injection Attacks
Anders Johansson explains why WordPress sites (powering 43% of the web) are prime targets for hackers, focusing specifically on SQL injectio
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
SymJack Attack Exploits AI Coding Agents for Supply Chain Compromise
This article describes a novel supply chain attack called 'SymJack' that targets AI coding agents. The attack exploits the trust and automat
176 malicious npm packages used dependency confusion to target internal dependencies and steal credentials
Sonatype researchers uncovered a campaign involving 176 malicious npm packages using a dependency confusion attack strategy. Attackers publi
