Cybersecurity experts have raised concerns about a potential supply chain breach affecting the software development firm BdThemes, leading to temporary restrictions on downloading its WordPress plugins. Unlike conventional software supply chain assaults, cybercriminals altered static remote JSON data streams within the official WordPress.org repository. This attack targeted plugins like Element Pack Addons for Elementor, Live Copy Paste for Elementor, Pixel Gallery Add-ons for Elementor, Prime Slider Add-ons for Elementor, Smart Admin Assistant, Ultimate Post Kit Add-ons for Elementor, and Ultimate Store Kit – all of which were affected by the malicious modifications.

The list includes 100,000+ active installs for the first three plugins and 6,000+ installs for the latter two.

Users who visited the plugin listings on the WordPress plugins directory have been informed that they are no longer available for download as of August 7 or 8, 2026, pending a "full review." The problem originates from an internal part named Biggopti, included within plugins. The primary payload is sent through the "api-data-all-records" API endpoint, utilizing a JavaScript file called "w2.js."

This script executes several tasks: Contacts the C2 server ("ia-cdn[. ]com/fz/c") with the victim website's origin to obtain targeting instructions. Since the credentials are deterministic, threat actors no longer need centralized lists of compromised sites, making incident responders easily able to compute exact usernames and passwords for targeted domain hunts.