惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
aimingoo的专栏
aimingoo的专栏
腾讯CDC
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
Engineering at Meta
Engineering at Meta
博客园_首页
B
Blog RSS Feed
D
Docker
M
MIT News - Artificial intelligence
爱范儿
爱范儿
I
InfoQ

TechSpot

Flagship Rematch: Ryzen 7 5800X3D vs. Core i9-12900K Typing with your brain might soon be as simple as wearing a beanie Slack chats and internal data from failed startups are finding a second life in AI training A $5 Bluetooth tracker hidden in a postcard exposed a warship's movements Leakers claim PlayStation 6 could offer at least 3x the performance of the PS5 The Mac Mini is no longer a niche product, it's local AI infrastructure IPv6 traffic reaches parity with IPv4 for the first time, Google data shows Xbox expansion cards are now cheaper than SSDs, and PC users are repurposing them Blue Origin prepares to reuse New Glenn booster in bid to challenge SpaceX Nvidia could bring back the 12GB RTX 3060 as supply issues disrupt GPU roadmap What was the first OS you ever used? SNK revives NeoGeo AES with modern upgrades and HDMI support Valve's Proton 11 beta boosts Linux gaming with better performance and classic game support Researchers warn Microsoft Defender vulnerability is already being exploited A four-day Steam freebie turned into $250,000 for an indie game AMD may relaunch Ryzen 7 5800X3D for AM4's 10th anniversary This humanoid robot can almost run as fast as a human sprinter Two New Jersey men jailed for helping North Korean IT workers infiltrate 100+ companies A $7,000 DIY radar project is taking on hardware that usually costs over $100,000 Metro 2039 is going darker than ever, launching this winter on PC and consoles Gemini arrives on macOS with a dedicated desktop app AI infrastructure boom pushes AMD, Intel and Arm to new valuation heights New self-healing material can repair itself over 1,000 times, extend the lifespan of cars and aircraft Japan's bullet train to debut high-tech private cabins, for an added fee Memory card and flash drive pricing surges 120%, with some models spiking 260% Open-source tool decrypts all private data collected by Windows Recall on Copilot PCs The 2026 PC and Console Gaming Report shows most revenue now comes from games outside the Top 20 PureMac is a new open-source macOS cleanup and app removal tool Your Airbnb host might actually be AI Steam might soon display 30-day price history for game deals
Popular WordPress plugins backdoored after ownership chan...
Alfonso Maruccia · 2026-04-16 · via TechSpot

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

A hot potato: WordPress plugins can significantly expand the native capabilities of the popular content management system, but they can also become a double edged sword. When malicious code finds its way into a widely used plugin ecosystem, the consequences can run amok fast and in unpredictable ways.

A popular brand of WordPress plugins was recently weaponized to download and spread malicious code. The new, potentially massive supply chain attack was unveiled by Austin Ginder, a WordPress developer and founder of the WP hosting service Anchor. The entrepreneur found that the threat was already affecting some Anchor customers, abusing a clever trick to keep C2 communications safe from easy takedown attempts.

Ginder's investigation began when an Anchor customer received an alert from the WordPress.org plugin team. The alert warned that a plugin named Countdown Timer Ultimate (CTU) contained potentially malicious code, including a backdoor that could be abused by a third party to gain unauthorized access to a WordPress website.

The plugin was part of a larger series developed by "Essential Plugin," an Indian brand that was recently acquired by an unknown party operating in the crypto and gambling business.

The CTU plugin was part of a larger plugin series developed by Essential Plugin (EP), an India based brand that was recently acquired by an unknown party operating in the crypto and gambling business. Soon after purchasing the roughly 30 plugins created by EP, the new owner added a backdoor to the codebases in their very first SVN commit.

The new owner added a backdoor to the codebases in their very first SVN commit.

The backdoor has been tracked and was added eight months ago, but it only received its first malware injection on April 6, 2026. The injected code contained some sophisticated payloads within a large block of PHP hidden inside wp-config.php, one of the central configuration files in a WordPress installation. The malware was designed to fetch spam links, trigger URL redirects, and generate fake pages.

The code responsible for checking for new instructions from the criminals' command and control server hid the server's domain inside an Ethereum smart contract. The attacker could update the smart contract with a new C2 domain at any time, making domain takedown attempts largely impractical.

After being warned about the issue, the WordPress.org plugin team removed all 30 or so plugins developed under the original EP brand. Ginder has provided a list of the plugins confirmed to be affected by the backdoor code, allowing WP admins to check whether their websites may now be at risk.

Ginder warns that this is the second instance of a malicious party taking over popular WordPress plugins to pursue malicious goals. The first case occurred in 2017 and affected a single plugin installed on 200,000 websites. The EP case operates at a much larger scale, with hundreds of thousands of potentially vulnerable WP sites.

The WordPress plugin marketplace is notorious for its ongoing security and trust issues. Right now, the WP team has no reliable system to flag plugins that have changed hands without site owners knowing. Things are unlikely to improve anytime soon before WordPress and WP Engine resolve their legal issues.