Audits

8 cleaned audits. · 217 IOCs catalogued.

Verdict: All (43) Malicious (14) Cleaned (8) Suspicious (8) Inconclusive (0) Benign (13) In progress (0)
Cleaned

Audit #53 InstaWP Connect – 1-click WP Staging & Migration — 40k+ installs

Verdict: malicious. On 2026-09-07, SVN r3684673 (instawp, message Update to version incident-14ypaj0acdw from GitHub) padded tailwind.config.js from ~2.2 KB to 9,794 bytes with a Node Ethereum-oracle C2 dropper. The pad…

by instawp · baseline 0.1.3.8 → head incident-14ypaj0acdw Instawp cluster · 6d ago
Cleaned

Audit #51 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … — 20k+ installs

Verdict: malicious — resolved. Advanced Responsive Video Embedder shipped an unauthenticated administrator-takeover backdoor in version 10.8.7, then shipped three further backdoor components in 10.8.8, the release whose…

baseline 10.8.6 → head 10.8.9 Nico23 cluster · 16 IOCs · 1mo ago
Cleaned

Audit #23 JS Help Desk – AI-Powered Support & Ticketing System — 7k+ installs

Historical audit. The proinstaller module shipped versions 1.0.3 through ~2.0.1 (2015-02 to 2017-03) carrying an eval(curl_exec(JCONSTINST)) primitive — a vendor-controlled remote-PHP-execution channel pointed at setup.…

baseline 1.0.3 → head 3.0.8 7 IOCs · 4mo ago
Cleaned

Audit #14 Social Sharing Plugin – Social Warfare — 10k+ installs

Confirmed malicious supply-chain compromise. Between 2024-04-05 and 2024-06-22 the WarfarePlugins wp.org committer account was used to push six tagged releases (4.4.6.4, 4.4.6.5, 4.4.6.6, 4.4.6.8, 4.4.6.9, 4.4.7.1) cont…

baseline 4.4.6.3 → head 4.4.7.1 17 IOCs · 4mo ago
Cleaned

Audit #20 Contact Form Multi-Step Addon — 300 installs

Confirmed malicious supply-chain compromise of themerex SVN account, recovered by the legitimate maintainer. Between 2024-06-23 22:47 UTC and 2024-06-24 04:10 UTC the themerex account was used to push two malicious "Upg…

by themerex · baseline trunk@r3071804 → head trunk@r3106511 2y ago
Cleaned

Audit #21 Simply Show Hooks — 1k+ installs

Confirmed malicious supply-chain compromise — stuartobrien SVN account compromised after 8-year dormancy. The plugin had been completely silent since 2016-10-27 (r1522935). On 2024-06-21 23:55 UTC the dormant account wa…

by stuartobrien · baseline trunk@r1522935 → head trunk@r3105891 2y ago
Cleaned

Audit #22 Wrapper Link Elementor — 700 installs

Confirmed malicious supply-chain compromise — and the only one in the wave that was self-cleaned by the legitimate author before PRT intervened. Between 2024-06-23 22:42 UTC and 2024-06-24 04:07 UTC the pedrogusmao02 SV…

by pedrogusmao02 · baseline trunk@r2903023 → head trunk@r3106508 2y ago
Cleaned

Audit #19 BLAZE Retail Widget — 10 installs

Confirmed malicious supply-chain compromise — 30 commits in a 28-hour burst. Between 2024-06-21 23:21 UTC and 2024-06-24 03:50 UTC the legitimate blazeretail SVN account was used to push 30 commits (all with the message…

by blazeretail · baseline trunk@r2268077 → head trunk@r3106494 8 IOCs · 2y ago