USENIX Security2022Top-tier venue
Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress Marketplaces
Ranjita Pai Kasturi, Jonathan Fuller, Yiting Sun, Omar Chabklo, Andres Rodriguez, Jeman Park, Brendan Saltaformaggio
Abstract
Modern websites owe most of their aesthetics and functionalities to Content Management Systems (CMS) plugins, which are bought and sold on widely popular marketplaces. Driven by economic incentives, attackers abuse the trust in this economy: selling malware on legitimate marketplaces, pirating popular plugins, and infecting plugins post-deployment. This research studied the evolution of CMS plugins in over 400K production webservers dating back to 2012. We developed YODA, an automated framework to detect malicious plugins and track down their origin. YODA uncovered 47,337 malicious plugins on 24,931 unique websites. Among these, 228K in revenues. Post-deployment attacks infected $834K worth of previously benign plugins with malware. Lastly, YODA informs our remediation efforts, as over 94% of these malicious plugins are still active today.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsYigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann et al.S&P 2026 · 12 citations
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud et al.USENIX Security 2024 · 10 citations
- Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment ReuseRunze Zhang, Mingxuan Yao, Haichuan Xu, Omar Alrawi et al.NDSS 2025
- CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property GraphFaysal Hossain Shezan, Zihao Su, Mingqing Kang, Nicholas Phair et al.NDSS 2023
- Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesHaichuan Xu, Runze Zhang, Mingxuan Yao, David Oygenblik et al.CCS 2025
Builds on8
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami et al.USENIX Security 2016 · 149 citations
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns et al.USENIX Security 2016 · 130 citations
- Surveylance: Automatically Detecting Online Survey ScamsAmin Kharraz, William K. Robertson, Engin KirdaS&P 2018 · 73 citations
- Leaky Images: Targeted Privacy Attacks in the WebCristian-Alexandru Staicu, Michael PradelUSENIX Security 2019 · 21 citations
Related papers
- TARDIS: Rolling Back The Clock On CMS-Targeting Cyber AttacksRanjita Pai Kasturi, Yiting Sun, Ruian Duan, Omar Alrawi et al.S&P 2020 · 14 citations
- From Payload to Plugin: Web-Scale Ecosystem Attribution of JavaScript Injection CampaignsRavindu De Silva, Nicholas Shao, Yigitcan Kaya, Mingxuan Yao et al.CCS 2026
- In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the WebJan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein et al.CCS 2025
- UntrustIDE: Exploiting Weaknesses in VS Code ExtensionsElizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck et al.NDSS 2024
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang et al.ASE 2023 · 31 citations
