Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
E-commerce Sites Targeted by Malware Through Okendo Widget

E-commerce Sites Targeted by Malware Through Okendo Widget

Posted on June 19, 2026 By CWS

An alarming supply chain attack has compromised thousands of e-commerce websites by turning a widely used third-party reviews widget into a vehicle for malware distribution. The attack leveraged the Okendo Reviews widget, a service utilized by more than 18,000 brands globally, to discreetly spread harmful software to unsuspecting users.

The attackers behind the SmartApeSG campaign managed to inject malicious JavaScript into the Okendo widget. This allowed them to deliver malware to visitors of affected online stores without detection. The script, embedded on high-traffic pages such as homepages and product listings, served as an ideal entry point for compromising a large audience.

Discovery and Response

The suspicious activity was first detected on May 14, 2026, by analysts at Zscaler ThreatLabz. They observed a surge in traffic associated with the SmartApeSG threat actor, prompting further investigation. The analysis revealed that the widget’s legitimate script contained hidden malicious code, highlighting a significant supply chain vulnerability.

SmartApeSG, also known as ZPHP and HANEYMANEY, is notorious for previous campaigns involving tools like NetSupport RAT and Remcos RAT. These tools enable attackers to remotely control victim computers or steal sensitive data. Upon discovering the breach, Zscaler promptly informed Okendo, which swiftly rectified the issue by cleaning the compromised script.

Technical Breakdown of the Attack

The attackers strategically targeted the Okendo widget to maximize their reach. By compromising a single, widely-used service instead of individual websites, they extended their impact significantly. The malicious script acted as a staged loader, executing its tasks incrementally and checking the environment before proceeding.

To avoid repeated execution, the script utilized browser-based tracking and filtered out mobile users, focusing on desktops due to the reliance on Windows-based interactions. Once the checks were satisfied, the script used an XOR-based method to decode and load further malicious content.

Scale and Impact of the Campaign

The attack’s scale was substantial, with the compromised widget appearing on websites of various sizes, from mid-tier online stores to major retail brands. Affected sites reported traffic ranging from 150,000 to several million monthly visitors, with one U.S. retail brand alone receiving about 7 million visitors monthly.

On the peak day of May 14, Zscaler recorded nearly 15,000 blocks related to SmartApeSG, indicating the campaign’s intensity. Although these figures represent blocked attempts rather than confirmed infections, they underscore the rapid spread potential of a supply chain attack when a popular vendor is compromised.

Website owners relying on third-party scripts like Okendo are advised to regularly audit their integrations and remain vigilant for any anomalies in their website behavior.

Stay updated with the latest cybersecurity developments by following us on Google News, LinkedIn, and X. Set CSN as your preferred source on Google for more instant updates.

Cyber Security News Tags:CAPTCHA, Cyberattack, Cybersecurity, data theft, e-commerce, JavaScript, Malware, Okendo, online threats, PowerShell, remote access tools, SmartApeSG, supply chain attack, ZPHP, Zscaler

Post navigation

Previous Post: CryptoBandits Malware Abuses Tor for RCE and Data Theft
Next Post: AI’s Role in Transforming Threat Management Strategies

Related Posts

Researchers Manipulate Stolen Data to Corrupt AI Models and Generate Inaccurate Outputs Researchers Manipulate Stolen Data to Corrupt AI Models and Generate Inaccurate Outputs Cyber Security News
Top Log Monitoring Tools to Watch in 2026 Top Log Monitoring Tools to Watch in 2026 Cyber Security News
Muddled Libra Exploits VMware vSphere in Cyber Attack Muddled Libra Exploits VMware vSphere in Cyber Attack Cyber Security News
Ransomware Hits 65% of Financial Firms in 2024 Ransomware Hits 65% of Financial Firms in 2024 Cyber Security News
Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Longwatch RCE Vulnerability Let Attackers Execute Remote Code With Elevated Privileges Cyber Security News
YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware YouTube Ghost Malware Network With 3,000+ Malicious Videos Attacking Users to Deploy Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • HazyBeacon Exploits AWS Lambda for Covert Cyber Operations
  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • HazyBeacon Exploits AWS Lambda for Covert Cyber Operations
  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark