Anatomy of a WordPress Supply Chain Attack
On 7 April 2026, the update infrastructure for a popular WordPress plugin was breached, and a compromised version was pushed through the official update channel to every site that checked for updates. One of those sites was a client's site we host at Blue 37. Here is what happened, what we found, and what it is making us change.