Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Unknown threat actors hijacked the update system for the Smart Slider 3 Pro plugin to distribute a poisoned version containing a backdoor, enabling remote code execution and persistent access.
Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35. Smart Slider 3 is a popular plugin with over 800,000 active installations. An unauthorized party gained access to Nextend’s update infrastructure and distributed a fully attacker-authored build through the official update channel. Any site that updated to 3.5.1.35 during a 6-hour window received a fully weaponized remote access toolkit. The trojanized update includes the ability to create rogue administrator accounts, drop backdoors for remote command execution via HTTP headers, and run arbitrary PHP code. It also establishes persistence in multiple locations, including a must-use plugin and the active theme's functions.php file. Data such as site credentials and database info were exfiltrated to the C2 domain 'wpjs1[.]com'. Users are advised to update to version 3.5.1.36 and perform a comprehensive manual cleanup of their files and databases.
Source: The Hacker News















