Proprietary 2019-01-01 · 2312 days ·Backdoor, Remote Access, Data Theft Potential

Meetanshi Magento extensions shipped license backdoors

Part of the Magento extension vendors shipped license backdoors campaign

Meetanshi extension downloads were part of the Magento license-backdoor campaign reported by Sansec. The affected vendor packages carried PHP backdoor code in license-check paths.

Story

Meetanshi was one of three Magento extension vendors Sansec named in its 2025 license-backdoor report. The affected artifacts were not random store infections; they were vendor-distributed extension ZIPs that customers could download and install as normal commercial software.

The inserted PHP posed as licensing code. Sansec reported fake License.php or LicenseApi.php paths loaded from extension registration code, with functions such as adminLoadLicense and adminUploadLicense able to execute attacker-controlled license content on the store.

Meetanshi is modeled separately from Tigren and MGS because its download site, package portfolio, and response were a distinct distribution boundary. Sansec reported that Meetanshi confirmed its server had been hacked while disputing that its software packages had been tampered with.

The operational risk was long dwell time. The campaign record carries the cross-vendor pattern and Sansec's estimate that hundreds to a thousand stores were running affected software; this page preserves the Meetanshi package names, download evidence, file indicators, and vendor-specific cleanup surface.

Affected Artifacts

Observed
2019-01-01 to 2025-05-01
Compromised Versions
Unknown
Fixed
Not listed
  • Sansec reported that Meetanshi confirmed its server had been hacked while disputing that its software had been tampered with.

Incident Context

Motive
Remote Access
Cause
Vendor Server Compromise
Transitive
No
User Impact
1000

External References

Source record: proprietary/meetanshi-magento-extensions/meta.yaml