A supply-chain attack compromising a popular WordPress plugin has resulted in backdoors being installed on approximately 1,500 websites. Security researchers have traced the incident to a breach of the plugin developer's own website, turning a routine update into a malware delivery channel.

The target was the distribution site for Admin Menu Editor Pro, a premium plugin for managing WordPress backend menus. Attackers compromised this site and pushed malicious updates to the plugin. Over 200 customers then installed the trojanized versions during normal update cycles.

The malicious payload was designed for stealth and persistence. Upon installation, it silently created a hidden administrator account with the username wpfilesmanager. This backdoor provided the attackers with ongoing access to the site, remaining concealed from the owner's user management dashboard.

Cybersecurity firm Wordfence, which investigated the incident, confirmed the root cause was the compromise of the plugin's distribution infrastructure. This method, where adversaries hijack trusted software update mechanisms, is a hallmark of supply-chain attacks.

The incident highlights a significant security gap in the WordPress ecosystem. Premium plugins distributed outside the official WordPress.org repository often lack the centralized security oversight and community review of the core directory. This reliance on developer-managed distribution sites creates a valuable target for attackers seeking widespread compromise.

For administrators, this event demands immediate action. Experts recommend the following audit and remediation checklist:

Immediate Response Steps:

  1. Audit User Accounts: Review all administrator accounts under Users > All Users. Look specifically for the wpfilesmanager account or any other unrecognized admin users.
  2. Verify Plugin Integrity: Check update logs or activity feeds for any "Admin Menu Editor Pro" installations around the time of the incident. The malicious versions have been identified.
  3. Remove the Threat: Immediately deactivate and delete any installed version of the plugin. Replace it with a clean version from a verified source or an alternative tool.
  4. Conduct a Full Site Scan: Use a dedicated security scanner like Wordfence or Sucuri to perform a comprehensive malware and vulnerability scan to detect any additional compromises.
  5. Reset All Credentials: Change all administrator passwords and review other user accounts to ensure no further compromise.

This attack is a stark reminder that a site's security perimeter extends to its entire supply chain. Administrators must treat third-party plugins and their distribution channels as critical components of their attack surface, implementing vigilant monitoring and regular audits as essential defenses.


一次針對流行WordPress插件的供應鏈攻擊,導致約1,500個網站被植入後門。安全研究人員已將事件追溯至插件開發商自身網站被入侵,使常規更新變成了惡意軟件的傳播渠道。

攻擊目標是Admin Menu Editor Pro的分銷網站,這是一款用於管理WordPress後台選單的付費插件。攻擊者入侵該網站並推送了惡意更新,其後超過200名客戶在常規更新週期中安裝了被植入木馬的版本。

該惡意負載專為隱蔽性和持久性而設計。安裝後,它會靜默創建一個用戶名為「wpfilesmanager」的隱藏管理員帳戶。這個後門使攻擊者能持續訪問網站,並隱藏於網站擁有者的用戶管理儀表板之外。

調查此事的網絡安全公司Wordfence證實,根本原因是插件分銷基礎設施被入侵。對手劫持可信軟件更新機制的方法,正是供應鏈攻擊的典型特徵。

此次事件凸顯了WordPress生態系統中的一個重大安全缺口。在官方WordPress.org儲存庫之外分發的付費插件,往往缺乏核心目錄所具備的集中式安全監督和社群審核。這種對開發商管理的分銷網站的依賴,為尋求大規模入侵的攻擊者創造了有價值的目標。

對於管理員而言,此事件需要立即採取行動。專家建議以下審計和補救清單:

即時應對步驟:

  1. 審計用戶帳戶: 在「用戶 > 所有用戶」下審核所有管理員帳戶。特別留意是否存在wpfilesmanager帳戶或任何其他未被識別的管理員用戶。
  2. 驗證插件完整性: 檢查更新日誌或活動動態,查找在事件發生期間是否有任何「Admin Menu Editor Pro」的安裝記錄。惡意版本已被識別。
  3. 移除威脅: 立即停用並刪除任何已安裝的該插件版本。用來自已驗證來源的乾淨版本或替代工具替換。
  4. 進行全面網站掃描: 使用如Wordfence或Sucuri等專用安全掃描器,進行全面的惡意軟件和漏洞掃描,以偵測是否有任何額外的入侵。
  5. 重置所有憑證: 更改所有管理員密碼,並審核其他用戶帳戶,確保沒有進一步的入侵。

這次攻擊是一個深刻的提醒:網站的安全邊界延伸至其整個供應鏈。管理員必須將第三方插件及其分發渠道視為攻擊面的關鍵組成部分,實施警覺的監控和定期審計作為必要的防禦措施。

新聞來源 / Original News Source