A dangerous plug-in was found on Wordpress.
A dangerous plug-in found on Wordpress can cause hackers to install Backdoors on websites.
According to a report by The Hacker News website, three popular plug-ins have been detected on Wordpress platforms: PushEngage, OptinMonster, and TrustPulse, all three of which were developed and are under the management of Awesome Motive. The plug-in was plugged by a group of hackers into a JavaScript file type of backdoor malware script inside a real plug-in, a supply chain attack or Supply Chain Attacks. The detection was by a research team from Sansec, a cybersecurity expert, on June 13, after which the plug-in was launched. PushEngage issued an Incident Notice to users of the hacking of the plug-in days later. But two other plug-ins, such as OptinMonster and TrustPulse, were not issued by the company.
The research team revealed a hacker attack period for embedding malicious code into the plug-in. The three plug-ins were found to have different malicious periods. OptinMonster and TrustPulse were detected for 25 minutes, from 22: 17 to 22: 42 (UTC Standard Time). While the PushEngage plug-in had a longer period of time, from June 12 to several hours, and June 14, it was detected that the counter was fired into the plug-in via the CDN Content Delivery Network. The research team estimated that about 1.2 million of these plug-in websites were at risk because the popularity of the plug-in was so high, because the OptinMonster plug-in had a million co-downloads, or even a less popular one like PushEngage had 9,000 downloads, but it must be reiterated that this was only the risk that malware could reach the site, not the amount of damage.
In case of how the malware code can infiltrate the plugin, the research team said that the hacking of the PushEngage plugin started as a hacker can hack into the server where the website for marketing the plugin is hosted through a security vulnerability inside the plugin for the Wordpress platform that the website is using, named UpdraftPlus, a backup plugin. But it must also be stated that the server that leads to this problem is a separate server from the server that manages the system of the plugin and the customer's data. After hacking it, the hacker will use the key. The CDN API Key instead shuffles the files that the CDN network itself sends into malware script files, but this is all just an assumption.
For malware scripts, when you look at the page View, it will not be unusual. But behind that, when the Admin or Administrator logs in, the code will use the Session of the Website Administrator to access the Full Permission to take over the Website:
Create an account with administrator-level privileges.
Install additional plugins that will not be displayed on the Dashboard that the system administrator uses. This will serve as a backdoor for hackers to control the website.
Send a new attendant account login code to a domain created by the hacker called tidio [.] cc.
The research team has recommended how to manage for those who suspect that the website is infected with malware. Follow the following steps:
Scan the Server-Side Scan website, as the malware plugin is not visible from the attendant dashboard.
Check for the System File in the wp-content / plugins folder, find a file called content-delivery-helper ("Content Delivery Helper") or database-optimizer, and find a foreign attendant account that was not created by yourself, such as developer _ api1 or any account named in dev _ xxxxxx, to delete.
Check the logs between June 12 and 14 if any foreign activity has occurred.
# Trending # Lemon 8 Howtoo # lemon 8 diary # Wordpress # freedomhack



















































