Open Source ·
phpBB links served malicious packages
phpBB download links for 3.2.2 were replaced for 181 minutes on January 26, 2018. The off-site packages carried extra code that tried to load remote JavaScript.
The phpBB incident was a link replacement attack, not a phpBB codebase exploit. On January 26, 2018, two official download links pointed away from phpBB's normal files to malicious packages on a third-party server.
The affected artifacts were the phpBB 3.2.2 full package and the automatic updater from 3.2.1 to 3.2.2. The altered packages added code that attempted to load JavaScript from a remote source. phpBB later controlled the referenced domains, which neutralized that path. Its final public update traced the redirects to its Cloudflare DNS configuration: an attacker used phpBB's unique Cloudflare API key to create a page rule for the two download URLs. phpBB said it had never used that API and did not store the key on its own servers, while Cloudflare found no compromise of its API-key system.
The window was short: 12:02 to 15:03 UTC, or 181 minutes. phpBB removed the links, told users to verify SHA256 hashes against the official download page, and asked anyone who installed or updated from the malicious packages to file an incident report.
phpBB estimated fewer than 500 downloads during the exposure window, with fewer likely used in production. The record is scoped to the official download-link compromise and the two package artifacts served through it.
Appendix · Affected releases
- phpBB estimated fewer than 500 downloads during the exposure window; the number of production installations was expected to be far lower.
- The malicious archive hash and injected filename were not published.
- phpBB estimated fewer than 500 downloads across both malicious packages; the number is exposure context, not a confirmed victim count.
- The malicious archive hash and injected filename were not published.
References
- [Security] phpBB 3.2.2 Packages Compromisedphpbb.com
- Hacker Compromised Official phpBB Download Linksbleepingcomputer.com
- phpBB Website Served Malicious Packagessecurityweek.com
Source record: oss/attacks/phpbb/meta.yaml