Another supply chain attack... this one at Okendo Reviews, a product review widget used on more than 18k online stores
A threat actor known as SmartApeSG added malicious JS code to prompt users with a ClickFix window
zscaler.com/blogs/security-res…
SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz
ThreatLabz identified a SmartApeSG-linked supply chain attack that targeted the Okendo Reviews widget impacting thousands of e-commerce sites.ThreatLabz (Zscaler)
reshared this
VessOnSecurity
in reply to Catalin Cimpanu • • •Francis Cook
in reply to Catalin Cimpanu • • •