SECURITYTHE HACKER NEWS
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after threat actors injected backdoor code into Pro plugin releases through official licensed update channels. Wordfence analyzed the incident, confirming the vendor's build and distribution pipeline was compromised.
Related Signal
Adjacent reporting
- Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
- Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged
- Someone planted backdoors in dozens of WordPress plugins used in thousands of websites
- Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers