Meetanshi Magento extensions shipped license backdoors
Part of the Magento extension vendors shipped license backdoors campaign
Meetanshi extension downloads were part of the Magento license-backdoor campaign reported by Sansec. The affected vendor packages carried PHP backdoor code in license-check paths.
Story
Meetanshi was one of three Magento extension vendors Sansec named in its 2025 license-backdoor report. The affected artifacts were not random store infections; they were vendor-distributed extension ZIPs that customers could download and install as normal commercial software.
The inserted PHP posed as licensing code. Sansec reported fake License.php or LicenseApi.php paths loaded from extension registration code, with functions such as adminLoadLicense and adminUploadLicense able to execute attacker-controlled license content on the store.
Meetanshi is modeled separately from Tigren and MGS because its download site, package portfolio, and response were a distinct distribution boundary. Sansec reported that Meetanshi confirmed its server had been hacked while disputing that its software packages had been tampered with.
The operational risk was long dwell time. The campaign record carries the cross-vendor pattern and Sansec's estimate that hundreds to a thousand stores were running affected software; this page preserves the Meetanshi package names, download evidence, file indicators, and vendor-specific cleanup surface.
Affected Artifacts
- Observed
- 2019-01-01 to 2025-05-01
- Compromised Versions
- Unknown
- Fixed
- Not listed
- Evidence
- distribution: meetanshi.com/media/downloads/Meetanshi_SocialLogin-2.0.5.zip, mirror: sansec.io/research/license-backdoor, file: License.php, file: LicenseApi.php , +4 more
- Sansec reported that Meetanshi confirmed its server had been hacked while disputing that its software had been tampered with.
Incident Context
- Motive
- Remote Access
- Cause
- Vendor Server Compromise
- Transitive
- No
- User Impact
- 1000
External References
- Magento supply chain attack compromises hundreds of e-storesbleepingcomputer.com
- Backdoor found in popular ecommerce componentssansec.io
- Sansec uncovered a supply chain attack via 21 backdoored Magento extensionssecurityaffairs.com
- Backdoor Activates in Magento Supply Chain Attack Impacting 1000 Storescyberinsider.com
- Hundreds of e-commerce sites hacked in supply-chain attackarstechnica.com
Source record: proprietary/meetanshi-magento-extensions/meta.yaml