Supply chain attack on BdThemes plugins: WordPress admin accounts created without the sites' knowledge.
A malicious actor compromised the upstream infrastructure of BdThemes, a premium WordPress plugin publisher, by poisoning a remote JSON feed to quietly create ghost admin accounts on affected sites. Several plugins totaling over 350,000 active installations have been removed from the WordPress.org repository.