Breaches · 2h ago

BigCommerce Finds App Breach Reaching Storefronts

BigCommerce alerted merchants that compromised credentials for third-party Ribon apps were used to inject malicious scripts into online stores, affecting multiple merchants. The company says active exploitation is confirmed, so this is not a theoretical supply-chain issue.

The attackers did not need to break into each storefront one by one. They used the app's legitimate access to write code through the normal integration path, which means the store itself inherited the app's trust and carried the injected script to customers.

For merchants that let outside apps modify customer-facing pages, the exposure sits in both places at once: the third-party app account and every storefront it could write to. Even after the credential problem is contained, any site that already accepted the script still has a cleanup problem of its own.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories