1 min readfrom InfoQ

Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them

Our take

In a striking security breach, an attacker acquired over 30 WordPress plugins on Flippa for a hefty six-figure sum, embedding a PHP deserialization backdoor in the initial commit. After an eight-month waiting period, the attacker activated the backdoor across 400,000 installations, leveraging Ethereum smart contracts for command and control. This incident highlights a critical vulnerability in WordPress.org, which lacks a mechanism for reviewing plugin ownership transfers—an oversight that platforms like npm and PyPI have addressed in their security protocols.
Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them

The WordPress plugin supply chain has long been a battleground for security, but the recent revelation that an attacker systematically compromised 30 plugins on Flippa for six figures—and waited eight months to activate a PHP deserialization backdoor across 400,000 installations—exposes a critical vulnerability in the platform’s infrastructure. This wasn’t a one-off breach; it was a calculated campaign leveraging Ethereum smart contracts for command-and-control operations, blending financial engineering with technical subterfuge. The attacker’s patience underscores a troubling truth: WordPress plugins, which power millions of websites, remain a prime target for sophisticated attacks. While the technical mechanics of the exploit—PHP deserialization flaws, stealthy backdoors—are well-documented, the broader issue lies in the lack of oversight around plugin ownership transfers. Unlike npm or PyPI, which audit code changes during ownership transitions, WordPress.org’s open marketplace allows malicious actors to inject compromised code without scrutiny. This gap isn’t just a technical oversight; it’s a systemic failure to adapt to modern software supply chain risks.

What makes this attack particularly insidious is its scale and duration. By purchasing plugins en masse, the attacker gained access to a vast network of sites, many of which likely rely on these tools for core functionality. The eight-month delay before activation suggests the malicious code was embedded in initial commits, lying dormant until the optimal moment to strike. This mirrors tactics seen in supply chain attacks on other platforms, where attackers target third-party dependencies to maximize impact. WordPress’s decentralized plugin ecosystem, while empowering developers, becomes a liability when ownership transfers lack accountability. The absence of a verification process for new owners—whether through code reviews or cryptographic attestations—creates a window for exploitation that’s hard to close without reimagining the platform’s governance model.

This incident also highlights the growing sophistication of cybercriminals in weaponizing legitimate marketplaces. Flippa, a platform for buying and selling website assets, is designed for convenience, not security. The attacker’s use of Ethereum smart contracts to resolve command-and-control relationships adds another layer of complexity, making attribution and mitigation even harder. While the WordPress community has historically relied on open-source collaboration and community vigilance, this attack reveals the limits of that approach. The absence of a centralized review mechanism for plugin ownership transfers leaves the ecosystem exposed to insider threats and coordinated campaigns. It’s a stark contrast to platforms like GitHub, where code changes are scrutinized by maintainers, or PyPI, which enforces stricter publication policies for packages.

The implications for WordPress users are profound. A compromised plugin can grant attackers access to sensitive data, administrative controls, or even entire websites. For businesses and organizations relying on these tools, the risk isn’t just technical—it’s existential. The attack serves as a wake-up call for the WordPress community to adopt stricter safeguards, such as mandatory code audits for plugin transfers or blockchain-based provenance tracking. As the article points out, the gap in oversight is not new, yet it remains unaddressed. This isn’t just about patching vulnerabilities; it’s about rethinking how trust is distributed in decentralized ecosystems.

Looking ahead, the WordPress community must confront the reality that its open architecture, while a strength, is also a vulnerability. The question isn’t whether such attacks will recur—it’s how quickly the ecosystem can evolve to mitigate them. As related reports reveal, similar tactics have been used before, suggesting a pattern that demands proactive solutions. The future of WordPress security may hinge on integrating lessons from other platforms, embracing automation, and prioritizing user safety over convenience. The stakes are too high to ignore.

An attacker purchased 30+ WordPress plugins on Flippa for six figures, planted a PHP deserialization backdoor in the first commit, and waited eight months before activating it across 400,000 installations. The attack used Ethereum smart contracts to resolve C2. WordPress.org has no mechanism for reviewing plugin ownership transfers, a gap that npm and PyPI addressed years ago.

By Steef-Jan Wiggers

Read on the original site

Open the publisher's page for the full experience

View original article
Attacker Bought 30 WordPress Plugins on Flippa and Backdoored All of Them | Beyond Market Intelligence