Hundreds of top ecommerce sites under attack following Magento supply chain flaw


- Sansec found 21 Magento extensions with malicious code
- The extensions belong to three companies, who claim everything’s in order
- Users are advised to take immediate action
Hundreds of ecommerce websites, including at least one major player, behemoth, have been compromised after poisoned Magento extensions woke up from a six-year slumber.
Cybersecurity researchers Sansec discovered the supply chain attack after one of its clients was targeted, ultimately finding 21 backdoored Magento extensions, belonging to three companies: Tigren, Meetanshi, and MSG. Here are their names:
Tigren Ajaxsuite
Tigren Ajaxcart
Tigren Ajaxlogin
Tigren Ajaxcompare
Tigren Ajaxwishlist
Tigren MultiCOD
Meetanshi ImageClean
Meetanshi CookieNotice
Meetanshi Flatshipping
Meetanshi FacebookChat
Meetanshi CurrencySwitcher
Meetanshi DeferJS
MGS Lookbook
MGS StoreLocator
MGS Brand
MGS GDPR
MGS Portfolio
MGS Popup
MGS DeliveryTime
MGS ProductTabs
MGS Blog
The long con
The company says some of the extensions were backdoored back in 2019. According to CyberInsider, the extensions were distributed via the vendors’ official download servers, which were “breached at some point”.
However, the attackers only activated the malicious code in April 2025. In the meantime, hundreds of ecommerce websites installed them, which resulted in the compromise of roughly 500 – 1,000 websites, including one owned by a $40 billion multinational corporation.
Sansec says that the attackers added a PHP backdoor to the license check file of all of the extensions, which allowed the threat actors to execute arbitrary PHP code remotely.
This granted them control over affected stores, compromising sensitive customer data and financial transactions in the process.
The researchers said they reached out to the three vendors with their findings, but got mixed responses.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Tigren denied having been breached and is allegedly still serving backdoored extensions, while Meetanshi confirmed having been breached but denied experiencing an extension compromise.
Finally, MGS did not even respond to Sansec’s inquiries, even though BleepingComputer confirmed the backdoor in at least one extension that’s currently on offer, for free, on the company website.
If you’re running a Magento store with any of the above-mentioned extensions, you should act immediately and secure your assets.
Via BleepingComputer
You might also like
Sansec found 21 Magento extensions with malicious code The extensions belong to three companies, who claim everything’s in order Users are advised to take immediate action Hundreds of ecommerce websites, including at least one major player, behemoth, have been compromised after poisoned Magento extensions woke up from a six-year slumber.…
Recent Posts
- Hundreds of top ecommerce sites under attack following Magento supply chain flaw
- Pinterest’s AI will help you find the ‘right words’ to search for fashion
- Waymo says it will add 2,000 more robotaxis in 2026
- This Thunderbolt 5 docking station can power four 8K monitors (in theory) – but it will come with a very expensive price tag
- Take a Tour of All the Essential Features in ChatGPT
Archives
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010