Tech

Hundreds of top ecommerce sites under attack following Magento supply chain flaw

Share
Share


  • Sansec found 21 Magento extensions with malicious code
  • The extensions belong to three companies, who claim everything’s in order
  • Users are advised to take immediate action

Hundreds of ecommerce websites, including at least one major player, behemoth, have been compromised after poisoned Magento extensions woke up from a six-year slumber.

Cybersecurity researchers Sansec discovered the supply chain attack after one of its clients was targeted, ultimately finding 21 backdoored Magento extensions, belonging to three companies: Tigren, Meetanshi, and MSG. Here are their names:

Tigren Ajaxsuite
Tigren Ajaxcart
Tigren Ajaxlogin
Tigren Ajaxcompare
Tigren Ajaxwishlist
Tigren MultiCOD
Meetanshi ImageClean
Meetanshi CookieNotice
Meetanshi Flatshipping
Meetanshi FacebookChat
Meetanshi CurrencySwitcher
Meetanshi DeferJS
MGS Lookbook
MGS StoreLocator
MGS Brand
MGS GDPR
MGS Portfolio
MGS Popup
MGS DeliveryTime
MGS ProductTabs
MGS Blog

The long con

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
AI image models gain creative edge by amplifying low-frequency features
Tech

AI image models gain creative edge by amplifying low-frequency features

Original vs C3 (Ours). Compared to the original diffusion models, Our C3...

Bilinear sequence regression model shows why AI excels at learning from word sequences
Tech

Bilinear sequence regression model shows why AI excels at learning from word sequences

Credit: Unsplash/CC0 Public Domain Researchers at EPFL have created a mathematical model...

How Europe can source critical raw materials at home
Tech

How Europe can source critical raw materials at home

Credit: Pixabay/CC0 Public Domain From Li-ion batteries and electric vehicles to drones...