Supply-chain attack injects backdoor on ShapedPlugin WordPress software
A supply-chain attack targeted ShapedPlugin, a WordPress plugin developer with more than 400,000 active installations across its free products. The backdoored premium plugin releases were distributed through the company's official update infrastructure. The malware provided attackers with persistent access to websites, stole administrator credentials and two-factor authentication (2FA) secrets, and deployed multiple remote access mechanisms. … The post Supply-chain attack injects backdoor on ShapedPlugin WordPress software appeared first on CyberInsider.
A supply-chain attack compromised ShapedPlugin's premium plugin products, injecting a backdoor that provided attackers with persistent access and stole administrator credentials and 2FA secrets.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at Cyber Insider.
