MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Smart Slider 3 Pro update infrastructure compromised to distribute backdoored release

On 7 April 2026, unauthorized actors gained access to Smart Slider 3 Pro's update infrastructure and made malicious version 3.5.1.35 available through the trusted update system for approximately six hours. The weaponized release could create unauthorized administrator accounts, execute commands, establish persistent backdoors and access credentials on WordPress and Joomla installations. Nextend shut down its update servers, removed the malicious version and released a clean replacement. The compromise of the legitimate vendor update channel constitutes a direct software-supply-chain data-integrity impact.

75

Estimated severity

75 / 100

90

Source reliability

90 / 100

Approximate Date

07/04/2026

Targeted Company

NEXTENDWEB

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Hungary

HUN

Other Affected Countries

No other affected countries reported

Target country

Hungary

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Software supply chain compromiseSoftware update compromiseBackdoorMalware

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.