Open Source · · 3 days

Social Warfare plugin created backdoors

Malicious code was injected directly into the Social Warfare plugin repository on WordPress.org.

Part of WordPress.org plugins created admin backdoors campaign

Social Warfare was the plugin that brought the June 2024 WordPress.org campaign into view. Wordfence learned of the compromise through a WordPress.org Plugin Review Team forum post, then used the malicious file to find four related plugin compromises.

Wordfence listed Social Warfare versions 4.4.6.4 through 4.4.7.1 as infected and 4.4.7.3 as patched. The risk was in the trusted update path: sites pulling plugin updates from WordPress.org received attacker code from the official channel.

The payload tried to create administrator accounts named Options or PluginAuth, sent the details to 94.156.79.8, and injected footer JavaScript for SEO spam. The plugin was later delisted while cleanup proceeded.

Social Warfare is useful as the anchor case because it exposed the campaign pattern. Once defenders understood the admin-user creation and footer injection logic in this plugin, the same indicators led them to the other compromised WordPress.org packages.

Appendix · Affected releases

social-warfare wordpress fixed 4.4.7.3
4.4.6.4 sha256 9e8d9826…0f6e80a3 download unavailable
4.4.7.1 sha256 168a7c42…d0827960 download unavailable
  • Immutable SVN changeset 3105893 is the first observed malicious trunk source state and declares version 4.4.6.4. Revision 3066437 is the preceding clean file; revision 3106384 is clean version 4.4.7.3.
  • The SHA-256 values identify complete 4.4.6.4 and 4.4.7.1 ZIPs recovered from the official WordPress distribution endpoint, in version order.

Indicators

  • file_sha256social-warfare-r3105893-social-warfare.php 9e8d9826bd7c91baecf7445cdb41f7bc16d8880fc1f73e521f2703b50f6e80a3

References

  1. Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
  2. Social Warfare malicious changeset 3105893plugins.trac.wordpress.org
  3. CVE-2024-6297 recordcveawg.mitre.org
  4. Various Plugins - Injected Backdoorwpscan.com

Source record: oss/attacks/wp-social-warfare/meta.yaml