BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
AI Summary
A supply chain attack on WordPress plugins distributed by BdThemes exploited a cross-site scripting (XSS) vulnerability in a remote JSON data stream used by the 'Biggopti' component. Attackers compromised a DigitalOcean Spaces bucket to inject malicious JavaScript payloads that execute in the browser of logged-in administrators, creating rogue admin accounts and deploying a PHP web shell. The attack does not modify plugin source code but instead poisons JSON responses, enabling silent exploitation on every wp-admin page load. Two payloads were identified: one retrieves targeting instructions from a C2 server, while the other generates deterministic credentials based on the victim's hostname, allowing attackers to access compromised sites without centralized credential storage.
AI-extracted · verify before operational use