Open Source · · 3 days

Simply Show Hooks plugin created backdoors

Malicious code was found in Simply Show Hooks 1.2.1 and 1.2.2 during the June 2024 WordPress.org plugin-repository compromise.

Part of WordPress.org plugins created admin backdoors campaign

Simply Show Hooks was not the plugin that first raised the alarm. The public WordPress.org Plugin Review Team notice was about Social Warfare; Wordfence used that Social Warfare sample to search for the same pattern and found four more affected plugins, including Simply Show Hooks.

Wordfence listed Simply Show Hooks 1.2.1 as infected and reported no patched version at publication time. The official CVE record includes 1.2.1 through 1.2.2, which agrees with the immutable repository history: the injected file first appeared while declaring 1.2.1 and remained in later revisions that declared 1.2.2. That keeps the incident in scope even though the plugin appears to have had no active installations reported publicly; the compromised artifact still sat in the WordPress.org plugin supply chain.

The injected PHP attempted to create administrator accounts named Options or PluginAuth, exfiltrated those details to 94.156.79.8, and added SEO-spam JavaScript in the site footer.

The risk model is the same as the larger campaign but the exposure is narrower. A site owner did not have to fetch a lookalike ZIP from a random domain; if they installed or updated the affected plugin through the repository while the malicious copy was available, the trusted update path could deliver the backdoor. This page keeps Simply Show Hooks separate because it had an unusual exposure profile. The campaign record carries the shared WordPress.org source-compromise pattern; this record is the inventory handle for the Simply Show Hooks artifact.

Appendix · Affected releases

simply-show-hooks wordpress
1.2.1 sha256 a356d8d8…d41a788f download unavailable
1.2.2 sha256 512fe66c…9dae69d9 download unavailable
  • The CVE record identifies versions 1.2.1 through 1.2.2 as affected; the previous dataset revision omitted 1.2.2.
  • Immutable SVN snapshot 3105888 has the longstanding clean 1.2.1 index.php; revision 3105889 is the first snapshot whose index.php contains the 94.156.79.8 backdoor. Revisions 3105890 and 3105891 retain the payload while changing the embedded plugin header to 1.2.2.
  • Revision 3106767, committed by the Plugin Review Team on 2024-06-24, restores the clean index.php. It is remediation evidence, not the injection changeset.
  • The WordPress.org support thread was the Plugin Review Team's Social Warfare notice, not a separate attack; Wordfence used it as the starting point for the broader five-plugin investigation.
  • Heise reported Simply Show Hooks 1.2.1 with no active installations, so this record models the compromised repository artifact rather than a known population of affected sites.

Indicators

  • file_sha256simply-show-hooks-r3105889-index.php a356d8d8d745ed6d2e8c38f4adcf9840ad327c02a5d98716f8d703acd41a788f
  • file_sha256simply-show-hooks-r3105890-index.php 512fe66cf86c27c87fdc65aaca8ee5558f9ba5f948d92dcaa06f71aa9dae69d9

References

  1. Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
  2. A Security Message from the Plugin Review Teamwordpress.org
  3. Plugin Review Team cleanup changeset 3106767plugins.trac.wordpress.org
  4. CVE-2024-6297 recordcveawg.mitre.org
  5. Various Plugins - Injected Backdoorwpscan.com
  6. WordPress Plugin Simply Show Hooks Malicious Code 1.2.1invicti.com
  7. Plugins on WordPress.org backdoored in supply chain attackbleepingcomputer.com
  8. Wordpress Five plug-ins infiltrated with malwareheise.de

Source record: oss/attacks/wp-simply-show-hooks/meta.yaml