ShapedPlugin's Official Update Server Delivered Backdoors for 28 Days
Attackers compromised ShapedPlugin's build pipeline on May 21 and used the company's own official update server to push credential-stealing backdoors to WordPress sites running three premium plugins — silently harvesting admin passwords, 2F...
Read article