radar.cysentrix
2 reports · 2 sources · tracked since 4d ago

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

AI synthesis Threat actors compromised ShapedPlugin's build pipeline, backdooring multiple WordPress plugins and distributing malicious updates to paying customers via the official update system.

supply chain
Why this ranks Transparent score: 14
coverage +6 source breadth +4 urgency +0 freshness +4

What changed

Coverage timeline

Every report remains linked to its original publisher.

  1. BleepingComputer First observed

    ShapedPlugin update flow hacked to infect WordPress sites ↗

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]

  2. The Hacker News Coverage expanded

    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack ↗

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdo...