











Attackers compromised the official update server for the Smart Slider 3 Pro WordPress plugin, distributing a malicious update that installed a backdoor on websites using the premium version.
The malicious update was available for approximately six hours, according to developer Nextendweb. The compromised plugin creates both a backdoor and a hidden administrator account. This secondary account remains active even if the plugin is removed, ensuring persistent access for the attackers. Similar tactics have been seen in other security events, including the Post SMTP plugin vulnerability.
Nextendweb has released a “cleanup” plugin designed to remove the malicious files and revert the unauthorized database changes. All customers who received the compromised update are advised to run the tool immediately. The attack shares characteristics with other supply-chain incidents like the GootLoader malware campaign. Security firm Patchstack published a technical analysis of the malware’s behavior.
Elles De Yeager
With a keen eye for cyber trends, Elles researches and writes about the technologies, threats, and defenses shaping our connected future.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。