hacker-news · Crawled Aug 11, 2026

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

4 IoCs
Read original article ↗

AI Summary

A supply chain attack on WordPress plugins distributed by BdThemes exploited a cross-site scripting (XSS) vulnerability in a remote JSON data stream used by the 'Biggopti' component. Attackers compromised a DigitalOcean Spaces bucket to inject malicious JavaScript payloads that execute in the browser of logged-in administrators, creating rogue admin accounts and deploying a PHP web shell. The attack does not modify plugin source code but instead poisons JSON responses, enabling silent exploitation on every wp-admin page load. Two payloads were identified: one retrieves targeting instructions from a C2 server, while the other generates deterministic credentials based on the victim's hostname, allowing attackers to access compromised sites without centralized credential storage.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain ia-cdn[.]com/fz/c Details →
Filename w2.js Details →
Filename x.js Details →
Filename emer-run.php Details →