EXECUTIVE SUMMARY
A recent supply chain attack on WordPress plugins has resulted in the compromise of five popular plugins, injecting them with malicious code. This attack aims to create rogue administrative user accounts and inject SEO spam via malicious JavaScript. The affected plugins have since been delisted from the WordPress plugin directory pending further review.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A recent supply chain attack on WordPress plugins has resulted in the compromise of five popular plugins, injecting them with malicious code. This attack aims to create rogue administrative user accounts and inject SEO spam via malicious JavaScript. The affected plugins have since been delisted from the WordPress plugin directory pending further review.[emaillocker id="1283"]
The compromised plugins include Social Warfare versions 4.4.6.4 – 4.4.7.1, Blaze Widget versions 2.2.5 – 2.5.2, Wrapper Link Element versions 1.0.2 – 1.0.3, Contact Form 7 Multi-Step Addon versions 1.0.4 – 1.0.5 and Simply Show Hooks version 1.2.1. The malicious code attempts to create new administrative user accounts with the usernames "Options" and "PluginAuth," and sends these details to an attacker-controlled server at IP address. Additionally, malicious JavaScript is injected into the footer of compromised websites to add SEO spam. The injected code is not heavily obfuscated and contains comments, making it relatively easy to identify.
Users with any of the affected plugins installed should consider their installations compromised and take immediate action. This includes inspecting WordPress administrative user accounts for unauthorized entries, deleting any suspicious accounts, and running a complete malware scan with the Wordfence plugin or Wordfence CLI. If infected plugins are detected, they should be updated to patched versions where available or removed entirely until secure versions are released. For further guidance on cleaning compromised WordPress sites, users can refer to the comprehensive guide provided by security experts or subscribe to incident response services for ongoing protection.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1195 | Supply Chain Compromise |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1078 | Valid Accounts |
| Defense Evasion | T1070 | Indicator Removal on Host |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1496 | Resource Hijacking |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html
[/emaillocker]