Cybersecurity — 2026-04-10

WordPress Plugin Smart Slider 3 Pro Backdoored via Supply Chain Attack on Nextend Update Servers

Attackers compromised Nextend's update infrastructure and distributed a weaponized build of Smart Slider 3 Pro through the official update channel. Sites that updated to version 3.5.1.35 between April 7 release and detection six hours later received a remote access toolkit capable of creating rogue admin accounts, executing system commands via HTTP headers, and exfiltrating credentials to the C2 domain wpjs1.com. The free version is unaffected. Over 800,000 installations use the plugin.

Analysis
The attack vector, compromising the official update channel rather than exploiting a plugin vulnerability, bypasses all site-level security measures. With 800,000+ installations across the free and Pro editions, the blast radius of even a 6-hour window is substantial. This is the second major WordPress supply chain attack this year, suggesting adversaries are optimizing for maximum distribution over sophistication.
3 sources
  1. Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers - The Hacker News
  2. Smart Slider updates hijacked to push malicious WordPress, Joomla versions - BleepingComputer
  3. Critical Supply Chain Compromise in Smart Slider 3 Pro: Full Malware Analysis - Patchstack

View in full brief →

UNCLASSIFIED // OPEN SOURCE