Tech

Hundreds of top ecommerce sites under attack following Magento supply chain flaw

Share
Share


  • Sansec found 21 Magento extensions with malicious code
  • The extensions belong to three companies, who claim everything’s in order
  • Users are advised to take immediate action

Hundreds of ecommerce websites, including at least one major player, behemoth, have been compromised after poisoned Magento extensions woke up from a six-year slumber.

Cybersecurity researchers Sansec discovered the supply chain attack after one of its clients was targeted, ultimately finding 21 backdoored Magento extensions, belonging to three companies: Tigren, Meetanshi, and MSG. Here are their names:

Tigren Ajaxsuite
Tigren Ajaxcart
Tigren Ajaxlogin
Tigren Ajaxcompare
Tigren Ajaxwishlist
Tigren MultiCOD
Meetanshi ImageClean
Meetanshi CookieNotice
Meetanshi Flatshipping
Meetanshi FacebookChat
Meetanshi CurrencySwitcher
Meetanshi DeferJS
MGS Lookbook
MGS StoreLocator
MGS Brand
MGS GDPR
MGS Portfolio
MGS Popup
MGS DeliveryTime
MGS ProductTabs
MGS Blog

The long con

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Perplexity AI’s Comet browser will streak across the web this month
Tech

Perplexity AI’s Comet browser will streak across the web this month

Perplexity AI’s new WhatsApp integration offers instant fact-checking without leaving the app...

Exploring the ‘Jekyll-and-Hyde tipping point’ in AI
Tech

Exploring the ‘Jekyll-and-Hyde tipping point’ in AI

Attention head (‘AI’) shown in basic form, generates a response to a...