ShapedPlugin’s paid update channel became the attack path, so the normal act of staying current could hand attackers access instead of safety. The malicious build hides as a fake WooCommerce plugin, wakes up when an admin opens WordPress, steals passwords, 2FA secrets, and database keys, and can write files on the server before it deletes itself.
The infected releases were pushed through the vendor’s official update system for three paid plugins: Product Slider Pro for WooCommerce before 3.5.4, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2. Wordfence said the backdoor was injected into ShapedPlugin’s Pro builds on May 21, with customer reports on June 10, infected copies confirmed on June 12, and the vendor acknowledging the incident on June 16.
This is the kind of compromise that survives the usual ‘check for unknown plugins’ response, because the payload installs itself under a hidden name and erases traces. The trust boundary that breaks here is the update channel itself, and that same problem can exist anywhere a vendor can push signed-looking software into customer systems.