Audits

11 audits. · 83 IOCs catalogued.

Verdict: All (11) Malicious (4) Cleaned (1) Suspicious (0) Inconclusive (0) Benign (6) In progress (0)

Suspect-shape but structurally unreachable — benign with one regression to flag. YARPP's version_info() matches the high-confidence catalog IOC unserialize_after_remote_call (@unserialize of wp_remote_post body, hardcod…

baseline 1.0 → head 5.30.11 · event #1741 · investigator austin

Historical PHP Object Injection chain in Admitad integration — gated since v6.0.0 (2023-08-21), endpoint dead. Two compounding patterns in application/libs/admitad/AdmitadProducts.php + application/libs/RestClient.php f…

baseline 11.0.0 → head 11.0.0 · event #1469 · investigator beacon-scan-skill
Cleaned Audit #14 Social Sharing Plugin – Social Warfare (20k+ installs) 17 IOCs 5d ago

Confirmed malicious supply-chain compromise. Between 2024-04-05 and 2024-06-22 the WarfarePlugins wp.org committer account was used to push six tagged releases (4.4.6.4, 4.4.6.5, 4.4.6.6, 4.4.6.8, 4.4.6.9, 4.4.7.1) cont…

baseline 4.4.6.3 → head 4.4.7.1 · event #1355 · investigator beacon-scan-skill
Malicious Closed by wp.org Audit #12 Scroll To Top (20k+ installs) 11 IOCs 7d ago

Update-checker hijack with active stored-XSS / RCE primitives served from a Panama-fronted C2. scroll-top (20,000 active installs) was sold by original author Ga Satrya (@gasatrya) to an actor identified as Benjamin (wp…

baseline → head 1.5.3 · event #728 · investigator beacon-scan-skill
Malicious Closed by wp.org Audit #10 Widget Logic (100k+ installs) by widgetlogics 8 IOCs 10d ago

Verdict: malicious. Confirmed supply-chain compromise matching the disclosed attack at anchor.host/how-i-caught-a-wordpress-plugin-supply-chain-attack and covered by TheNextWeb, Yahoo Tech, BigGo, byteiota, and others. …

baseline 5.10.4 → head 6.0.0 · event #103 · investigator austin

Verdict: legitimate team onboarding — not a takeover. alexopen is a Smash Balloon employee ("Alex at Smash Balloon" display name), added as a committer to the five Smash Balloon social-feed plugins owned by Awesome Moti…

baseline 6.9.1 → head 6.10.0 · event #114 · investigator austin
Malicious Closed by wp.org Audit #4 33-plugin suite (180k+ combined installs) by essentialplugin 15 IOCs 10d ago

Marketplace acquisition of an established 30-plugin portfolio used as a vehicle for a fleet-wide PHP-deserialization RCE backdoor with on-chain C2 resolution. A buyer identified only as "Kris" purchased the entire Essen…

baseline 2.6.6 → head 2.6.9.1 · event #104 · investigator austin
Malicious Closed by wp.org Audit #13 Quick Page/Post Redirect Plugin (70k+ installs) by anadnet 12 IOCs 22d ago

The original author intentionally weaponized wordpress.org distribution to seed an out-of-band update channel they controlled — and then served tampered builds through that channel after the wp.org-distributed code went…

baseline 5.2.1 → head 5.2.4 · investigator manual