Supply Chain Attack Compromised 100,000 WordPress Sites via Poisoned Cloud Storage
Over 100,000 WordPress sites were simultaneously compromised in a coordinated supply chain attack targeting a DigitalOcean Spaces bucket used by BdThemes plugins' BigOpti component. Attackers gained write access to this third-party cloud storage and served malicious JSON responses containing an unsanitized display_id parameter, which executed XSS payloads the moment any logged-in administrator opened their dashboard. A script called w2.js then automated three actions: connecting to command-and-control servers, creating rogue admin accounts, and planting hidden web shells in WordPress directories. A secondary payload used a Base36 hashing algorithm to derive valid admin credentials deterministically from a site's hostname alone, eliminating the need for attackers to maintain a database of compromised targets. Traditional File Integrity Monitoring tools flagged no issues because the core plugin files on disk remained unmodified — the malicious code was delivered dynamically over the network at runtime.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in