BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create unauthorized admin accounts on WordPress sites running BdThemes plugins. The attack targeted administrators' browsers to inject malicious configuration.
- Disclosed
- Last updated
- Blast radius
- BdThemes plugin users; WordPress sites running affected BdThemes plugins
- Ecosystems
- Attack vectors
- Affected entities
- BdThemes pluginsPremium WordPress web-design tools
BdThemes, a developer of premium WordPress web-design tools, suffered a supply-chain compromise when a threat actor gained access to the company's upstream infrastructure. The attacker modified a remote JSON feed that is delivered to administrators' browsers, allowing them to inject malicious code that created rogue administrator accounts on affected WordPress installations.\n\nThis attack vector leverages the trust relationship between plugin users and the vendor's update/configuration servers. By compromising the upstream infrastructure rather than the plugins themselves, the attacker was able to affect all users of BdThemes plugins without requiring a malicious package release or code commit.\n\nThe incident demonstrates the risk of relying on remote configuration feeds and the importance of securing upstream infrastructure that delivers code or configuration to end-user systems.
Indicators of compromise
- Packages
- BdThemes plugins
Remediation
- Audit all WordPress admin accounts on sites running BdThemes plugins for unauthorized accounts created during the compromise window
- Change passwords for all WordPress administrator accounts
- Review WordPress user logs and audit trails for suspicious account creation or privilege escalation
- Update BdThemes plugins to patched versions once available
- Verify the integrity of BdThemes' update servers and JSON feed sources
- Implement additional authentication controls such as two-factor authentication on WordPress admin accounts
- Monitor for indicators of compromise such as unauthorized admin logins or configuration changes
Sources
- BdThemes plugins supply-chain hack creates rogue WordPress admins · BleepingComputer
Cite this entry
"BdThemes plugins supply-chain hack creates rogue WordPress admins." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed August 10, 2026; last updated August 10, 2026. https://supplychainattack.org/incident/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins-15lzx1
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedhigh
OptinMonster WordPress plugin hacked in CDN supply-chain attack
OptinMonster, TrustPulse, and PushEngage WordPress plugins were compromised in a supply-chain attack targeting Awesome Motive's content distribution network (CDN). The compromise affected plugin distribution and delivery to end users.
Container registryOtherUpdate-server compromise - containedhigh
Hola Browser for Windows compromised to deliver cryptominer
The Windows version of Hola Browser was compromised in a supply chain attack that delivered an undeclared cryptocurrency miner executable to users. The compromise affected the browser's distribution or update mechanism.
OtherCompromised packageUpdate-server compromise - activecritical
ChainDrop npm Worm: Bun-loaded CI/CD credential harvester with Ethereum dead-drop C2
ChainDrop is a self-propagating npm worm that publishes malicious versions of dozens of npm packages using stolen maintainer credentials. The worm harvests CI/CD credentials and uses an Ethereum-based dead-drop command-and-control mechanism.
ChaindropnpmOtherCompromised packageMalicious maintainerAccount takeover - containedhigh
Online ad firm Adform’s script compromised to steal cryptocurrency
Adform's advertising script was compromised in a supply-chain attack that injected cryptocurrency-stealing code. The malicious script intercepted wallet addresses copied to visitors' clipboards and replaced them with attacker-controlled addresses, affecting all websites using Adform's ad platform.
OtherCompromised package