<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[This whole thing is more than a little bit concerning.]]></title><description><![CDATA[<p>This whole thing is more than a little bit concerning. </p><p>Sharing for any of my friends who use Wordpress and its plugin marketplace. </p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/" title="Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.">
<img src="https://anchor.host/wp-content/uploads/2026/04/wordpress-plugin-supply-chain-attack-1.webp" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">
Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.
</a>
</h5>
<p class="card-text line-clamp-3">Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into</p>
</div>
<a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://anchor.host/wp-content/uploads/2015/07/logo-512x512-55b0fb3cv1_site_icon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />







<p class="d-inline-block text-truncate mb-0">Anchor Hosting <span class="text-secondary">(anchor.host)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/53aa7dd8-cb80-4cfa-b888-4694771a55cc/this-whole-thing-is-more-than-a-little-bit-concerning.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 03:31:49 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/53aa7dd8-cb80-4cfa-b888-4694771a55cc.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 13 Apr 2026 15:22:31 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 20:43:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> There are so many things they could do to make this kind of operation less lucrative, less effective, more risky, etc. and it's very telling that they won't.</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116399343142978107</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116399343142978107</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Mon, 13 Apr 2026 20:43:44 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 20:42:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> From the perspective of capitalist walled-garden plugin repositories, this is everything working as intended.</p><p>You're *supposed* to be able to monetize people's trust in you by selling that to malicious parties, duh.</p><p>🤬</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116399337320931374</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/dalias/statuses/116399337320931374</guid><dc:creator><![CDATA[dalias@hachyderm.io]]></dc:creator><pubDate>Mon, 13 Apr 2026 20:42:15 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 20:40:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> Thank you <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":)" alt="🙂" /></p>]]></description><link>https://board.circlewithadot.net/post/https://kirche.social/users/Numerfolt/statuses/116399328836811850</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://kirche.social/users/Numerfolt/statuses/116399328836811850</guid><dc:creator><![CDATA[numerfolt@kirche.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 20:40:05 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 18:49:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> I stopped using WordPress this year because of how many people try to hack it everyday.</p>]]></description><link>https://board.circlewithadot.net/post/https://indieweb.social/users/perlman/statuses/116398893713699501</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://indieweb.social/users/perlman/statuses/116398893713699501</guid><dc:creator><![CDATA[perlman@indieweb.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 18:49:26 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 18:37:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> I probably shouldn't be surprised that the market for fraud is so lucrative that buying an entire company to turn it into an engine for backdooring websites is a potentially profitable move.</p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/kgourlay/statuses/116398845865683108</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/kgourlay/statuses/116398845865683108</guid><dc:creator><![CDATA[kgourlay@tech.lgbt]]></dc:creator><pubDate>Mon, 13 Apr 2026 18:37:16 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 18:05:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games" rel="nofollow noreferrer noopener">@<span>britt</span></a></span> holy moly</p>]]></description><link>https://board.circlewithadot.net/post/https://boop.bleepbop.space/users/cb/statuses/01KP409J8Q73M3K5863Y4YHQ20</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://boop.bleepbop.space/users/cb/statuses/01KP409J8Q73M3K5863Y4YHQ20</guid><dc:creator><![CDATA[cb@boop.bleepbop.space]]></dc:creator><pubDate>Mon, 13 Apr 2026 18:05:08 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 17:55:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> I'm really surprised this isn't being talked about more. We saw an alert in WP Admin last week and quickly patched our sites, but this is the first mention I've seen of this in the wild.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/stepschwarz/statuses/116398680163601964</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/stepschwarz/statuses/116398680163601964</guid><dc:creator><![CDATA[stepschwarz@mastodon.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 17:55:07 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 16:55:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> I always hated those commercial 3rd party plugins. I never trusted them. This was one reason to switch from Wordpress to Hugo.</p>]]></description><link>https://board.circlewithadot.net/post/https://norden.social/users/kielkontrovers/statuses/116398445565814696</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://norden.social/users/kielkontrovers/statuses/116398445565814696</guid><dc:creator><![CDATA[kielkontrovers@norden.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 16:55:28 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 15:45:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> Thanks for the heads up. I don't use WP but know lots of people that do.</p>]]></description><link>https://board.circlewithadot.net/post/https://beige.party/users/Alison/statuses/116398169513813095</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://beige.party/users/Alison/statuses/116398169513813095</guid><dc:creator><![CDATA[alison@beige.party]]></dc:creator><pubDate>Mon, 13 Apr 2026 15:45:15 GMT</pubDate></item><item><title><![CDATA[Reply to This whole thing is more than a little bit concerning. on Mon, 13 Apr 2026 15:32:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/britt%40mstdn.games">@<span>britt</span></a></span> “And here is the wildest part. It resolved its C2 domain through an Ethereum smart contract, querying public blockchain RPC endpoints. Traditional domain takedowns would not work because the attacker could update the smart contract to point to a new domain at any time.”</p><p>Clever</p>]]></description><link>https://board.circlewithadot.net/post/https://sfba.social/users/jonathankoren/statuses/116398119555978914</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sfba.social/users/jonathankoren/statuses/116398119555978914</guid><dc:creator><![CDATA[jonathankoren@sfba.social]]></dc:creator><pubDate>Mon, 13 Apr 2026 15:32:33 GMT</pubDate></item></channel></rss>