Threat Advisory

Recent Supply Chain Attack on WordPress Plugins Compromises Five Popular Plugins

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A recent supply chain attack on WordPress plugins has resulted in the compromise of five popular plugins, injecting them with malicious code. This attack aims to create rogue administrative user accounts and inject SEO spam via malicious JavaScript. The affected plugins have since been delisted from the WordPress plugin directory pending further review.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A recent supply chain attack on WordPress plugins has resulted in the compromise of five popular plugins, injecting them with malicious code. This attack aims to create rogue administrative user accounts and inject SEO spam via malicious JavaScript. The affected plugins have since been delisted from the WordPress plugin directory pending further review.[emaillocker id="1283"]

The compromised plugins include Social Warfare versions 4.4.6.4 – 4.4.7.1, Blaze Widget versions 2.2.5 – 2.5.2, Wrapper Link Element versions 1.0.2 – 1.0.3, Contact Form 7 Multi-Step Addon versions 1.0.4 – 1.0.5 and Simply Show Hooks version 1.2.1. The malicious code attempts to create new administrative user accounts with the usernames "Options" and "PluginAuth," and sends these details to an attacker-controlled server at IP address. Additionally, malicious JavaScript is injected into the footer of compromised websites to add SEO spam. The injected code is not heavily obfuscated and contains comments, making it relatively easy to identify.

Users with any of the affected plugins installed should consider their installations compromised and take immediate action. This includes inspecting WordPress administrative user accounts for unauthorized entries, deleting any suspicious accounts, and running a complete malware scan with the Wordfence plugin or Wordfence CLI. If infected plugins are detected, they should be updated to patched versions where available or removed entirely until secure versions are released. For further guidance on cleaning compromised WordPress sites, users can refer to the comprehensive guide provided by security experts or subscribe to incident response services for ongoing protection.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1195 Supply Chain Compromise
Execution T1059 Command and Scripting Interpreter
Persistence T1078 Valid Accounts
Defense Evasion T1070 Indicator Removal on Host
Exfiltration T1041 Exfiltration Over C2 Channel
Impact T1496 Resource Hijacking

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html

[/emaillocker]
crossmenu