A supply-chain attack on BdThemes plugins created rogue WordPress admin accounts via a compromised JSON feed. Learn how to protect your site from this hidden threat.
If you run a WordPress site, you probably rely on plugins to make your life easier. They handle everything from page builders to security, and you rarely think twice about them. But a recent attack on BdThemes, a popular developer of premium WordPress design tools, should make you pause. A threat actor didn't hack individual websites—they went straight for the source, compromising the company's upstream infrastructure and turning a routine update into a backdoor for rogue admin accounts.
Here's the scary part: the attack didn't rely on a phishing email or a stolen password. Instead, the hackers modified a remote JSON feed that BdThemes delivers to administrators' browsers. When you logged into your dashboard, that feed quietly executed code that created new admin accounts you never asked for. Those accounts gave the attacker full control over your site, including the ability to install malware, steal customer data, or wipe everything clean.
### How the Supply-Chain Attack Worked
Supply-chain attacks are nasty because they exploit trust. You're not just trusting the plugin developer—you're trusting everyone they work with, every server they use, and every tool in their pipeline. In this case, the attacker found a weak point in BdThemes' infrastructure and used it to inject malicious instructions into that JSON feed.
Here's what that meant in practice:
- The feed was delivered to your browser during normal admin activity.
- It contained code that silently created new WordPress admin users.
- Those accounts had full privileges, so the attacker could log in anytime.
- The rogue admins were hidden, making them hard to spot unless you knew what to look for.
This wasn't a random exploit. It was targeted, coordinated, and designed to stay under the radar. The worst part? Most site owners had no idea anything was wrong until it was too late.
### Why This Matters for Your WordPress Site
If you use any BdThemes products—and many people do—you need to treat this as a serious wake-up call. Even if you haven't seen any suspicious activity, your site could already be compromised. Rogue admin accounts don't always act immediately. Sometimes they sit dormant for weeks, waiting for the right moment to strike.
Think of it this way: your website is like your front door. You lock it, you check the windows, but if the locksmith who made your key was compromised, then all that effort doesn't matter. The attacker already has the keys.
### What You Should Do Right Now
First, don't panic. Panic leads to bad decisions. Instead, take a methodical approach to securing your site. Here's a step-by-step plan:
1. **Check your admin users immediately.** Go to your WordPress dashboard and look at the Users section. If you see any accounts you don't recognize, delete them right away.
2. **Change all your passwords.** This includes your admin password, database password, and any FTP or hosting credentials. Use a password manager to generate strong, unique passwords.
3. **Update everything.** If BdThemes has released a patched version of their plugins, install it immediately. Outdated versions are a magnet for attackers.
4. **Scan for malware.** Use a reputable security plugin like Wordfence or Sucuri to scan your site for malicious code. Look for anything that doesn't belong.
5. **Enable two-factor authentication.** This adds an extra layer of protection, so even if someone gets your password, they can't log in without a second code.
### The Bigger Lesson for Website Owners
This attack is a reminder that no plugin is 100% safe. Even the most reputable developers can be compromised. That doesn't mean you should abandon plugins altogether—that's not practical—but it does mean you need to be proactive about security.
Here are a few habits that can save you a lot of trouble down the road:
- **Keep your plugins to a minimum.** Every plugin you install is another potential entry point for attackers.
- **Audit your admin accounts regularly.** Make it a monthly habit to check who has access to your site.
- **Back up your site frequently.** If something goes wrong, you want to be able to restore everything quickly.
- **Stay informed.** Follow security news and pay attention when a plugin you use is mentioned in a breach.
### Final Thoughts
The BdThemes supply-chain hack is a sobering reminder that the digital world is full of hidden dangers. But knowledge is power. Now that you know what happened, you can take steps to protect yourself. Don't wait for the next attack—act today. Check your admin users, update your plugins, and make security a priority. Your website is your digital home, and it's worth defending.
Stay safe out there, and remember: the best defense is a good offense.