BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Summary

WordPress plugin vendor BdThemes has been compromised in a supply chain attack where malicious code was injected into JSON files, allowing attackers to create rogue administrator accounts. The WordPress.org plugins team has temporarily disabled downloads of affected plugins as a result of this sophisticated attack.

IFF Assessment

FOE

This is bad news for defenders as it represents a successful supply chain attack leading to unauthorized administrator access in WordPress sites.

Defender Context

This incident highlights the ongoing risks associated with software supply chain attacks, particularly in widely used platforms like WordPress. Defenders need to be vigilant about the integrity of plugins and themes, and monitor for any unexpected changes or unauthorized administrator accounts.

Read Full Story →