Article may be outdated

This article is 64 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

From a 7 KB file to a 13-year backdoor operation

V
ValentineC
From a 7 KB file to a 13-year backdoor operation
AI Summary

A security researcher discovered a long-running backdoor operation involving 27 WordPress plugins that had been active since 2013. The investigation revealed that a single operator used multiple accounts to distribute malicious code disguised as legitimate software.

Why it matters

This incident exposes significant vulnerabilities in open-source plugin ecosystems and the potential for long-term supply chain attacks.

Dive DeeperCreate a free account to unlock

Most plugin closures are uneventful. A developer stops responding, wp.org pulls the plugin, the listing goes dark, and that is the end of it. My WP Beacon scanner flags these all day long. I glance at them and move on.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
Political Bias
Center
LeftLean LCenterLean RRight
Confidence: 90%

The report is a technical breakdown of a security discovery based on forensic evidence.

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in