Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Compromised Admin Menu Editor Pro update server distributed backdoored plugin versions installing web shells and hidden admin accounts on roughly 1,500 WordPress sites.
A threat actor with root-level access to adminmenueditor.com pushed trojanized Admin Menu Editor Pro versions 2.35 and 2.36 containing includes/wp-user-consent.php, which installed a web shell and created a hidden wp_-prefixed user account. At least 230 customers and roughly 1,500 sites installed the malicious update, with several hundred more downloads possibly affected. Developer Janis Elsts took the site offline after the attacker recompromised the clean 2.36 release; version 2.34 and the free plugin are believed unaffected.
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers hijacked HBO Max's verified Reddit account to run 108 ClickFix ads delivering infostealers and crypto clippers to Windows and macOS users.
Hudson Rock and ADAMnetworks linked the hijacked u/hbomax Reddit account to a campaign they call PasteSwitch, which ran 108 malicious ads over roughly 48 hours pushing sites like hbomaxx.us, codex-craft.com, and code-desktop.com. ClickFix social engineering tricks victims into pasting Base64-obfuscated shell or PowerShell commands into Terminal or Run, delivering MacSync, AMOS helper persistence, Amatera Stealer loaded in-memory, and the AnimateClipper and ZigClipper crypto clipboard hijackers. Windows chains used an MP3/HTA polyglot to create scheduled tasks, disable AMSI, and launch 32-bit PowerShell; fake Ledger, Trezor Suite, and Exodus wallet apps steal recovery phrases. Reddit admins paused the ads, and it remains unclear how the account was accessed.
Twitch extension with 30K installs exposes users’ OAuth tokens
Twitch extension with 30,000+ installs exfiltrates users' OAuth session tokens to Russian-run JeetBot proxy servers.
Socket analysis shows the "Twitch Enhanced Viewer | JeetBot" browser extension, with over 30,000 installs on the official Chrome and Firefox stores, captures the Twitch web client's authorization header and extracts the user's OAuth token. The token is appended as an auth= URL parameter to video playlist requests routed through JeetBot proxy servers, landing in cleartext request logs retrievable by the Russian-language bot service vendor; ten hardcoded Russian-language channels are exempted. Earlier versions used more explicit token exfiltration, and the extension remained live in both stores at publication. Socket recommends removing the extension, disconnecting all Twitch sessions, and re-authenticating.