Security News > 2022 > September > Hackers breach software vendor for Magento supply-chain attacks

Hackers breach software vendor for Magento supply-chain attacks
2022-09-13 15:21

Hackers have injected malware in multiple extensions from FishPig, a vendor of Magento-WordPress integrations that count over 200,000 downloads.

The intruders took control of FishPig's server infrastructure and added malicious code to the vendor's software to gain access to websites using the products, in what is described as a supply-chain attack.

Security researchers at Sansec, a company offering eCommerce malware and vulnerability detection services, have confirmed the compromise of 'FishPig Magento Security Suite' and 'FishPig WordPress Multisite'.

Php, a file that validates licenses in premium FishPig plugins, which downloads a Linux binary from FishPig's servers.

The company has published a security advisory recommending an upgrade of all FishPig modules.

The best advice for people at the minute is to reinstall all FishPig modules.


News URL

https://www.bleepingcomputer.com/news/security/hackers-breach-software-vendor-for-magento-supply-chain-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Magento 3 52 119 27 11 209