AI Briefing
KO

Someone bought 30 WordPress plugins and planted a backdoor in all of them

·2026.04.14 09:40

Key point

A supply chain backdoor was planted in more than 30 WordPress plugins.

Details

The same attacker bought 30+ WordPress plugins, then inserted backdoor code into the first commit, contaminating the supply chain.

The malicious code lay dormant for about 8 months before activating in early April 2026, after which it caused spam links and redirects on multiple sites.

Key points are as follows.

  • Target: numerous WordPress plugins
  • Method of infiltration: backdoor inserted into the initial commit after acquisition
  • Dormancy period: about 8 months
  • Damage pattern: spam links and redirect spread after activation

This case shows that seizing control of a plugin distribution chain allows a single manipulation to affect many sites at once.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.