By Interestana AI Editorial — AI-drafted, human-overseen. How we report
BdThemes Supply Chain Attack Creates Rogue WordPress Admins
A threat actor successfully compromised the upstream infrastructure of BdThemes, a developer known for its premium WordPress web-design tools, to create unauthorized administrator accounts on websites utilizing their plugins. The attack involved modifying a remote JSON feed that was delivered to administrators' browsers. This feed, when processed by the affected WordPress sites, contained malicious instructions that enabled the creation of new, rogue admin users. The compromise was identified and disclosed by Wordfence, a cybersecurity firm specializing in WordPress security.
Wordfence's investigation revealed that the threat actor gained access to BdThemes' infrastructure and injected malicious code into a legitimate JSON file. This file was then served to WordPress sites that had BdThemes plugins installed and configured to fetch updates or settings from this feed. When the affected WordPress sites processed this compromised JSON feed, the malicious instructions were executed, leading to the creation of new administrator accounts. These accounts were not created by legitimate users or administrators but were surreptitiously added by the attackers. The specific plugins affected were not explicitly named in the initial report, but the attack vector targeted the update or configuration mechanism that relied on the remote JSON feed.
The implications of such an attack are significant. By creating rogue administrator accounts, the threat actor could gain full control over the affected WordPress websites. This level of access allows for a wide range of malicious activities, including defacing websites, stealing sensitive data such as user credentials or payment information, injecting malware, redirecting traffic to malicious sites, or using the compromised sites to launch further attacks. The supply chain nature of this attack means that a single compromise at the developer level can have a widespread impact on numerous end-users, highlighting the critical importance of securing the development and distribution pipelines for software.
Wordfence has provided guidance to users of BdThemes products, recommending that they immediately update all BdThemes plugins to their latest versions. Updating the plugins is crucial as it ensures that any malicious code injected into the JSON feed will be overwritten or neutralized by the legitimate code in the updated plugin. Furthermore, website administrators are advised to review their WordPress user lists for any unfamiliar or unauthorized administrator accounts and to remove them promptly. Implementing robust security practices, such as using strong, unique passwords for all administrative accounts, enabling multi-factor authentication, and regularly auditing user access, can further mitigate the risks associated with such supply chain compromises. The incident underscores the ongoing challenges in securing the digital supply chain and the need for continuous vigilance from both software developers and end-users.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.