BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A Sneaky Supply Chain Attack Hits WordPress Sites, Leaving a Trail of Rogue Admins in Its Wake

A sophisticated cyber attack has been discovered targeting BdThemes, a popular WordPress theme provider. The malicious scheme involves injecting poisoned JSON files into the supply chain, which ultimately creates rogue administrators on compromised sites. This brazen attack not only raises concerns about the security of WordPress-based websites but also underscores the importance of keeping software and plugins up to date.

The attackers’ modus operandi is as follows: they inject a malicious script into BdThemes’ JSON files, which are then distributed to affected sites through auto-updates. Once executed, this script creates new administrators with elevated privileges, effectively giving hackers unfettered access to the website’s backend. The implications are alarming – with complete control over the site, attackers can manipulate content, steal sensitive data, or even use the compromised platform as a launching pad for further attacks.

The attack is particularly insidious because it exploits the very nature of software updates, which are typically seen as a trusted and secure process. However, in this case, the poisoned JSON files have been carefully crafted to blend in with legitimate code, making it challenging for even skilled administrators to detect the malware. This highlights the importance of scrutinizing every aspect of the update process, including any third-party libraries or dependencies.

The compromised sites affected by this attack include a wide range of WordPress-powered blogs and websites, many of which cater to specific niches or communities. While BdThemes has since removed the malicious files from their distribution channels, the damage may already be done – administrators are urged to immediately review their site’s administrator list for any suspicious new accounts.

As the cybersecurity landscape continues to evolve, it’s essential that users remain vigilant and proactive in securing their online presence. This attack serves as a stark reminder of the importance of keeping software and plugins up to date, scrutinizing every aspect of the update process, and regularly monitoring one’s site’s administrator list for any signs of malicious activity.

If you’re a WordPress administrator, take this opportunity to review your site’s security posture by:

* Verifying the integrity of all auto-updated files

* Regularly reviewing the administrator list for suspicious new accounts

* Ensuring that all plugins and themes are updated to their latest versions

* Implementing robust backup and monitoring solutions to detect potential threats early on

By staying informed and taking proactive measures, you can help safeguard your WordPress site from similar supply chain attacks in the future.


Source: The Hacker News — 2026-08-11