Silent Sabotage: A Long-Dormant Threat Emerges in E-commerce Software Ecosystem
In a troubling revelation, cybersecurity analysts have identified a stealthy and complex supply chain compromise embedded within 21 widely deployed e-commerce applications. This covert campaign leveraged legitimate third-party software to infiltrate digital storefronts at scale.
What sets this breach apart is its chilling latency: although the malicious code was implanted between 2019 and 2022, it lay dormant for years—only surfacing with active exploitation beginning April 20, 2025. This calculated delay points to an unusually patient and methodical adversary with a long-term agenda.
At the heart of the breach is a counterfeit licensing system cleverly disguised inside extensions from notable software vendors. The tampered files—bearing innocuous names like License.php and LicenseApi.php—quietly established a covert access point into store infrastructure. The attackers exploited a function called adminLoadLicense, which executes dynamic content supplied via manipulated license uploads.
Earlier versions of the compromised extensions provided little to no safeguards, while later builds incorporated weak checksum-based authentication tied to specific vendors. Despite these efforts, the attackers preserved a modular and adaptive backdoor architecture—changing filenames, paths, and authorization techniques to sidestep traditional detection methods.
The campaign has so far been traced to modules from three confirmed vendors: Tigren, Meetanshi, and Magesolution. A fourth vendor, Weltpixel, is under scrutiny, although investigators have not yet concluded whether their systems were directly compromised or if downstream integrations were exploited individually.
Initial impact assessments suggest between 500 and 1,000 e-commerce businesses may currently be running infected software. This underscores how profoundly damaging supply chain threats can be—enabling threat actors to quietly compromise entire networks by hijacking trust in popular tools.




