Tech

Hundreds of top ecommerce sites under attack following Magento supply chain flaw

Share
Share


  • Sansec found 21 Magento extensions with malicious code
  • The extensions belong to three companies, who claim everything’s in order
  • Users are advised to take immediate action

Hundreds of ecommerce websites, including at least one major player, behemoth, have been compromised after poisoned Magento extensions woke up from a six-year slumber.

Cybersecurity researchers Sansec discovered the supply chain attack after one of its clients was targeted, ultimately finding 21 backdoored Magento extensions, belonging to three companies: Tigren, Meetanshi, and MSG. Here are their names:

Tigren Ajaxsuite
Tigren Ajaxcart
Tigren Ajaxlogin
Tigren Ajaxcompare
Tigren Ajaxwishlist
Tigren MultiCOD
Meetanshi ImageClean
Meetanshi CookieNotice
Meetanshi Flatshipping
Meetanshi FacebookChat
Meetanshi CurrencySwitcher
Meetanshi DeferJS
MGS Lookbook
MGS StoreLocator
MGS Brand
MGS GDPR
MGS Portfolio
MGS Popup
MGS DeliveryTime
MGS ProductTabs
MGS Blog

The long con

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
How AI can protect forests
Tech

How AI can protect forests

The proposed pipeline for change detection in high threat zones in forests....

Google’s Gemini AI Is now a Pokémon Master
Tech

Google’s Gemini AI Is now a Pokémon Master

Google’s Gemini 2.5 Pro has officially completed Pokémon Blue The game ran...

Physical cloaking works like a disappearing act for structural defects
Tech

Physical cloaking works like a disappearing act for structural defects

Researchers created microstructures to shield a defect shaped like a rabbit. Credit:...

A big data approach for next-generation battery electrolytes
Tech

A big data approach for next-generation battery electrolytes

Credit: Chemistry of Materials (2025). DOI: 10.1021/acs.chemmater.4c03196 Discovering new, powerful electrolytes is...