bleeping-computer · Crawled Aug 10, 2026

BdThemes plugins supply-chain hack creates rogue WordPress admins

3 IoCs
Read original article ↗

AI Summary

A supply-chain attack on BdThemes, a developer of premium WordPress plugins, allowed a threat actor to compromise its infrastructure and inject malicious JavaScript into a remote JSON feed used by its plugins. This feed is loaded in the WordPress admin dashboard, where the attacker exploited a cross-site scripting (XSS) vulnerability in the Biggop Library to create rogue administrator accounts on affected sites. The attack was stealthy, required no user interaction, and used a webshell for persistence. The same actor is believed to be behind recent similar attacks on other WordPress plugins.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain sigmative[.]com Details →
Filename w2.js Details →
Filename emer-run.php Details →