Interestana
Home/News/BdThemes Supply Chain Attack Creates Rogue WordPress Admins
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

BdThemes Supply Chain Attack Creates Rogue WordPress Admins

BdThemes Supply Chain Attack Creates Rogue WordPress Admins

Cybersecurity researchers have identified a supply chain compromise targeting BdThemes, a vendor of plugins for the WordPress content management system (CMS). This attack involved the malicious modification of JSON files, which are commonly used for data interchange and configuration within software applications. Unlike typical software supply chain attacks that alter source code directly within official repositories, this incident uniquely involved the poisoning of JSON data. According to Wordfence researcher Paolo Tresso, "zero source code files were modified within the official WordPress.org repository." This means the core code hosted on WordPress.org remained untainted, but the data used by the plugins was compromised.

The consequence of this attack was the creation of unauthorized administrator accounts on WordPress websites that utilized the affected BdThemes plugins. Attackers leveraged the compromised JSON files to inject malicious code that would execute during the plugin's installation or update process. This code then established new administrative users with elevated privileges, effectively giving the attackers control over the affected websites. The WordPress plugins team responded to the threat by temporarily disabling downloads of BdThemes plugins from the official WordPress.org repository to prevent further infections. This action highlights the critical importance of securing not only source code but also configuration and data files within the software development and distribution pipeline.

Supply chain attacks, in general, exploit trust relationships between software vendors and their customers. By compromising a trusted vendor like BdThemes, attackers can reach a wide audience of users who have installed the vendor's plugins. The WordPress ecosystem, with its vast number of plugins and themes, is a particularly attractive target for such attacks. The method employed in this BdThemes incident, focusing on JSON file manipulation, represents a sophisticated approach that bypasses traditional code-scanning defenses. It underscores the evolving tactics of threat actors and the need for continuous vigilance and advanced security measures across all components of the software supply chain, including data files and configuration settings. The temporary disabling of downloads serves as a protective measure while the vulnerability is investigated and remediated, aiming to restore user confidence and secure the platform.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next