BigCommerce alerted merchants that compromised credentials for third-party Ribon apps were used to inject malicious scripts into online stores, affecting multiple merchants. The company says active exploitation is confirmed, so this is not a theoretical supply-chain issue.
The attackers did not need to break into each storefront one by one. They used the app's legitimate access to write code through the normal integration path, which means the store itself inherited the app's trust and carried the injected script to customers.
For merchants that let outside apps modify customer-facing pages, the exposure sits in both places at once: the third-party app account and every storefront it could write to. Even after the credential problem is contained, any site that already accepted the script still has a cleanup problem of its own.
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.