Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Magento supply chain attack compromises hundreds of e-stores
    Security

    Magento supply chain attack compromises hundreds of e-stores

    PineapplesUpdateBy PineapplesUpdateMay 3, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Magento supply chain attack compromises hundreds of e-stores
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Magento supply chain attack compromises hundreds of e-stores

    The attack of a supply chain associated with the 21 Backdore Magento Extension has signed an agreement between 500 and 1,000 e-commerce stores, with a $ 40 billion multinational.

    Researchers at SANSEC discovered the attack report that some extensions had returned by 2019, but the malicious code was only active in April 2025.

    “Many vendors were hacked into a coordinated supply chain attack, SANSEC found 21 applications with a single back door,” SANSEC explains,

    “Eagerly, malware was injected 6 years ago, but came into life this week because the attackers took full control of the ecommerce server.”

    SANSEC says that Tigraine, Meetanshi and MGS are from the compromised extension vendors:

    • Tigraine Ajaxuit
    • Tigraine ajakcart
    • Tigraine Ajaxalogin
    • Tigraine ajakskompere
    • Tigraine ajaksavishalist
    • Tigraine multicode
    • Meetanshi imageclane
    • Meetanshi Kukiyotis
    • Meetanshi flatship
    • Meetings FacebookChat
    • Meetanshi curanisvic
    • Meetanshi Diferz
    • MGS Lookbook
    • MGS storage
    • MGS brand
    • MGS GDPR
    • MGS portfolio
    • MGS popup
    • MGS deliverytime
    • Mgs producttabs
    • MGS blog

    SANSEC has also found a compromise version of Weltpixel Googletagmanager Extension, but cannot confirm whether the point of compromise was on the seller or the website.

    In all views, the extension includes a PHP backdoor that is added to the license check file (license, or license or licenseapi.php) used by the extension.

    This malicious code checks for HTTP requests, which contain special parameters called “requestkey” and “datasign”, which are used to check against hardcode keys within PhP files.

    Checking HTTP request for valid authentication against hardcoded keys
    Checking HTTP request for valid authentication against hardcoded keys
    Source: Bleepingcomputer

    If the check is successful, the backdoor files the other administrator access to the functions, allowing a remote user to upload a new license and save it as a file.

    Running a administrator function specified in http request
    Running a administrator function specified in http request
    Source: Bleepingcomputer

    This file is then included using the “included_onus ()” PhP function, which loads the file and automatically executes any code within the uploaded license file.

    Adept
    Adept
    Source: Bleepingcomputer

    The previous versions of the back door did not require certification, but new ones use a hardcode key.

    SANSEC told Bleepingcomputer that this back door was used to upload a webshal on one of his customer’s sites.

    Given the ability to upload and run any PHP code, the possible results of the attack include data theft, skimmer injection, arbitrary administrator account building, and more.

    SANSEC approached three vendors, warning them of the back door discovered. The cyber security firm says that MGS did not respond, Tigraine denied a violation and continued to distribute the backdoor extension, and Meetanshi admitted to a server breech, but not an extension agreement.

    Bleepingcomputer independently confirmed that it is present in the backdoor MGS Storelocator extension, which is free to download from their site. We did not confirm whether the backdoor is present in other extensions reported by Sansec.

    Users of the mentioned extension are recommended to scan a full server for indicators of SANSEC shared in their report and restore the site from a known-clean backup if possible, if possible.

    SANSEC commented on the peculiarity of the backdoor for laying inactivity for six years and now activated and promised to provide additional insight by their ongoing investigation.

    Bleepingcomputer contacted three vendors, but no response was received at this time.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Attack chain compromises estores hundreds Magento supply
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to communicate with astronauts in ISS
    Next Article I tried to find out a great website content monitoring equipment change for beginners with low budget and small businesses
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Your Bluetooth headphones may be under attack – here’s what to do next

    January 15, 2026
    Startups

    Your smart home is at risk – 6 ways to protect your devices from attack

    December 6, 2025
    AI/ML

    Crowdfunding tips from Helen Lay of Crowd Supply

    October 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    This browser is designed for those who never close tabs

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.