ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack, affecting Pro plugin builds distributed through the vendor's Easy Digital Downloads infrastructure. The compromised plugins incorporate a loader that fetches a payload from a remote se…
Intelligence analysis by Llama 3.3 70B

The supply chain attack compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases. The affected plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro.
Imagine you bought a legitimate software update, but it had a hidden backdoor that allowed hackers to access your site. That's what happened with some WordPress plugins. The hackers compromised the software update process, so even legitimate updates had malware. It's like finding a Trojan horse in a trusted package.
Analysis
Supply Chain Attack Vector
The attack on ShapedPlugin's WordPress Pro plugins is a prime example of a supply chain attack, where the attacker targets the vendor's build and distribution pipeline to inject malicious code into the software. This type of attack can be particularly devastating, as it can compromise even legitimate software updates and affect a large number of users.
The attackers managed to tamper with the official release channels and push backdoor code into the Pro plugin releases distributed through the vendor's Easy Digital Downloads infrastructure. The compromised plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro.
Malware Capabilities
The malware incorporated into the compromised plugins is capable of capturing credentials in plaintext and two-factor authentication (2FA) codes. It also establishes multiple persistence methods, enabling arbitrary file writes via a custom REST endpoint when provided a specific authentication token. Additionally, it can drop a web shell with command execution features, allowing the attackers to execute arbitrary commands on the compromised site.
Impact and Mitigation
The impact of this attack can be significant, as it exposes site owners who purchased legitimate licenses and installed updates directly from the vendor's official update system to malware. To mitigate the attack, site owners are recommended to reset all passwords, revoke and regenerate 2FA secrets for all users, review administrator accounts for unauthorized additions, and check mail plugin configurations for modified SMTP credentials.
Security Measures
To prevent such attacks in the future, it is essential to implement robust security measures, including monitoring and securing the build and distribution pipeline. This can include implementing code signing, using secure protocols for software updates, and conducting regular security audits and testing. Additionally, users should be cautious when installing software updates and should only install updates from trusted sources.
Key points
- Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack
- The affected plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro
- The malware incorporated into the compromised plugins can capture credentials and establish persistence methods
The incident highlights the importance of supply chain security, and the vendor's prompt response and efforts to review and secure their distribution and release processes are a positive step. Additionally, the incident raises awareness about the risks of supply chain attacks and the need for users to be vigilant when installing software updates.
The attack on ShapedPlugin's WordPress Pro plugins is a concerning example of the risks of supply chain attacks. The fact that the attackers were able to compromise the vendor's build and distribution pipeline and push backdoor code into legitimate software updates is a significant concern. If left unchecked, such attacks can have devastating consequences for users and organizations.



