Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Northgard Devs is back with a cartoni high-fantasy action-RPG, set to launch in beta later this year

    June 9, 2025

    Turn Setup 16-inch 4K OLED portable monitor review

    June 9, 2025

    Cyberbedrohunn Erkenon An Regierane: NDR, EDR UND XDR Anarschadit

    June 9, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Magento supply chain attack compromises hundreds of e-stores
    Security

    Magento supply chain attack compromises hundreds of e-stores

    PineapplesUpdateBy PineapplesUpdateMay 3, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Magento supply chain attack compromises hundreds of e-stores
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Magento supply chain attack compromises hundreds of e-stores

    The attack of a supply chain associated with the 21 Backdore Magento Extension has signed an agreement between 500 and 1,000 e-commerce stores, with a $ 40 billion multinational.

    Researchers at SANSEC discovered the attack report that some extensions had returned by 2019, but the malicious code was only active in April 2025.

    “Many vendors were hacked into a coordinated supply chain attack, SANSEC found 21 applications with a single back door,” SANSEC explains,

    “Eagerly, malware was injected 6 years ago, but came into life this week because the attackers took full control of the ecommerce server.”

    SANSEC says that Tigraine, Meetanshi and MGS are from the compromised extension vendors:

    • Tigraine Ajaxuit
    • Tigraine ajakcart
    • Tigraine Ajaxalogin
    • Tigraine ajakskompere
    • Tigraine ajaksavishalist
    • Tigraine multicode
    • Meetanshi imageclane
    • Meetanshi Kukiyotis
    • Meetanshi flatship
    • Meetings FacebookChat
    • Meetanshi curanisvic
    • Meetanshi Diferz
    • MGS Lookbook
    • MGS storage
    • MGS brand
    • MGS GDPR
    • MGS portfolio
    • MGS popup
    • MGS deliverytime
    • Mgs producttabs
    • MGS blog

    SANSEC has also found a compromise version of Weltpixel Googletagmanager Extension, but cannot confirm whether the point of compromise was on the seller or the website.

    In all views, the extension includes a PHP backdoor that is added to the license check file (license, or license or licenseapi.php) used by the extension.

    This malicious code checks for HTTP requests, which contain special parameters called “requestkey” and “datasign”, which are used to check against hardcode keys within PhP files.

    Checking HTTP request for valid authentication against hardcoded keys
    Checking HTTP request for valid authentication against hardcoded keys
    Source: Bleepingcomputer

    If the check is successful, the backdoor files the other administrator access to the functions, allowing a remote user to upload a new license and save it as a file.

    Running a administrator function specified in http request
    Running a administrator function specified in http request
    Source: Bleepingcomputer

    This file is then included using the “included_onus ()” PhP function, which loads the file and automatically executes any code within the uploaded license file.

    Adept
    Adept
    Source: Bleepingcomputer

    The previous versions of the back door did not require certification, but new ones use a hardcode key.

    SANSEC told Bleepingcomputer that this back door was used to upload a webshal on one of his customer’s sites.

    Given the ability to upload and run any PHP code, the possible results of the attack include data theft, skimmer injection, arbitrary administrator account building, and more.

    SANSEC approached three vendors, warning them of the back door discovered. The cyber security firm says that MGS did not respond, Tigraine denied a violation and continued to distribute the backdoor extension, and Meetanshi admitted to a server breech, but not an extension agreement.

    Bleepingcomputer independently confirmed that it is present in the backdoor MGS Storelocator extension, which is free to download from their site. We did not confirm whether the backdoor is present in other extensions reported by Sansec.

    Users of the mentioned extension are recommended to scan a full server for indicators of SANSEC shared in their report and restore the site from a known-clean backup if possible, if possible.

    SANSEC commented on the peculiarity of the backdoor for laying inactivity for six years and now activated and promised to provide additional insight by their ongoing investigation.

    Bleepingcomputer contacted three vendors, but no response was received at this time.


    Red Report 2025

    Based on the analysis of 14M malicious tasks, search for the top 10 MITERAT & CK techniques behind the 93% attacks and how to defend them against them.

    Attack chain compromises estores hundreds Magento supply
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow to communicate with astronauts in ISS
    Next Article I tried to find out a great website content monitoring equipment change for beginners with low budget and small businesses
    PineapplesUpdate
    • Website

    Related Posts

    Security

    Cyberbedrohunn Erkenon An Regierane: NDR, EDR UND XDR Anarschadit

    June 9, 2025
    Security

    New Mirai Botnet infected TBK DVR device through command injection flour

    June 8, 2025
    Security

    Remove project directors presented as malicious NPM package utilities

    June 8, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025624 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025559 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025498 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    My Kitchen Book of The Week Review: ‘Bread Baking for beginners’ will give you all the confidence you need

    May 17, 20250 Views

    Mantra (OM) and Movement Labs (Move) token Scandal are shaking Crypto Market-Making

    May 17, 20250 Views

    12 free movie streaming sites with no sign up requirements

    May 17, 20250 Views
    Our Picks

    Northgard Devs is back with a cartoni high-fantasy action-RPG, set to launch in beta later this year

    June 9, 2025

    Turn Setup 16-inch 4K OLED portable monitor review

    June 9, 2025

    Cyberbedrohunn Erkenon An Regierane: NDR, EDR UND XDR Anarschadit

    June 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.