THREAT OPS › Threat News › PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
<p>The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress plugins directory. Currently, all the affected plugins are temporarily closed pending a full inspection and ongoing investigation by the WordPress Plugins team.</p> <p>Our investigation revealed a
MITRE ATT&CK techniques
Indicators of compromise
- 1024732009983dd5e54b4cf5593f04d4md5
- 7719cd98a35ffad2771f26d1ceab7d27md5
- 9aadc3e5c5242b273bd17c5bdc358845md5
- e450ae5bc4bfc0d960dded06a76bb8e9md5
- https://optinmonster.com/security-incident-tampered-script-served-via-optinmonster-and-trustpulse/#what-to-check-and-dourl
- wordpress.orgdomain
- ia-cdn.comdomain
- 40wordpress.orgdomain
- api.sigmative.iodomain
- developer.wordpress.orgdomain