Skip to content
supplychainattack.orgSupply chain attack incident catalog
containedcritical

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create unauthorized admin accounts on WordPress sites running BdThemes plugins. The attack targeted administrators' browsers to inject malicious configuration.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
BdThemes plugin users; WordPress sites running affected BdThemes plugins
Ecosystems
Attack vectors
Affected entities
  • BdThemes pluginsPremium WordPress web-design tools

BdThemes, a developer of premium WordPress web-design tools, suffered a supply-chain compromise when a threat actor gained access to the company's upstream infrastructure. The attacker modified a remote JSON feed that is delivered to administrators' browsers, allowing them to inject malicious code that created rogue administrator accounts on affected WordPress installations.\n\nThis attack vector leverages the trust relationship between plugin users and the vendor's update/configuration servers. By compromising the upstream infrastructure rather than the plugins themselves, the attacker was able to affect all users of BdThemes plugins without requiring a malicious package release or code commit.\n\nThe incident demonstrates the risk of relying on remote configuration feeds and the importance of securing upstream infrastructure that delivers code or configuration to end-user systems.

Indicators of compromise

Packages
  • BdThemes plugins

Remediation

  • Audit all WordPress admin accounts on sites running BdThemes plugins for unauthorized accounts created during the compromise window
  • Change passwords for all WordPress administrator accounts
  • Review WordPress user logs and audit trails for suspicious account creation or privilege escalation
  • Update BdThemes plugins to patched versions once available
  • Verify the integrity of BdThemes' update servers and JSON feed sources
  • Implement additional authentication controls such as two-factor authentication on WordPress admin accounts
  • Monitor for indicators of compromise such as unauthorized admin logins or configuration changes

Sources

  1. BdThemes plugins supply-chain hack creates rogue WordPress admins · BleepingComputer

Cite this entry

"BdThemes plugins supply-chain hack creates rogue WordPress admins." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins-15lzx1

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedhigh

    OptinMonster WordPress plugin hacked in CDN supply-chain attack

    OptinMonster, TrustPulse, and PushEngage WordPress plugins were compromised in a supply-chain attack targeting Awesome Motive's content distribution network (CDN). The compromise affected plugin distribution and delivery to end users.

    Container registryOtherUpdate-server compromise
  2. containedhigh

    Hola Browser for Windows compromised to deliver cryptominer

    The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.

    OtherCompromised packageUpdate-server compromise
  3. activecritical

    ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2

    ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.

    ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover
  4. containedhigh

    Online ad firm Adform’s script compromised to steal cryptocurrency

    Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.

    OtherCompromised package