Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress Marketplaces
Ranjita Pai Kasturi, Jonathan Fuller, Yiting Sun, Omar Chabklo, Andres Rodriguez, Jeman Park, Brendan Saltaformaggio
摘要
Modern websites owe most of their aesthetics and functionalities to Content Management Systems (CMS) plugins, which are bought and sold on widely popular marketplaces. Driven by economic incentives, attackers abuse the trust in this economy: selling malware on legitimate marketplaces, pirating popular plugins, and infecting plugins post-deployment. This research studied the evolution of CMS plugins in over 400K production webservers dating back to 2012. We developed YODA, an automated framework to detect malicious plugins and track down their origin. YODA uncovered 47,337 malicious plugins on 24,931 unique websites. Among these, 228K in revenues. Post-deployment attacks infected $834K worth of previously benign plugins with malware. Lastly, YODA informs our remediation efforts, as over 94% of these malicious plugins are still active today.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot PluginsYigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann 等S&P 2026 · 被引用 12 次
- DVa: Extracting Victims and Abuse Vectors from Android Accessibility MalwareHaichuan Xu, Mingxuan Yao, Runze Zhang, Mohamed Moustafa Dawoud 等USENIX Security 2024 · 被引用 10 次
- Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment ReuseRunze Zhang, Mingxuan Yao, Haichuan Xu, Omar Alrawi 等NDSS 2025
- CHKPLUG: Checking GDPR Compliance of WordPress Plugins via Cross-language Code Property GraphFaysal Hossain Shezan, Zihao Su, Mingqing Kang, Nicholas Phair 等NDSS 2023
- Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesHaichuan Xu, Runze Zhang, Mingxuan Yao, David Oygenblik 等CCS 2025
它引用的顶会 Paper8
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 被引用 345 次
- You've Got Vulnerability: Exploring Effective Vulnerability NotificationsFrank Li, Zakir Durumeric, Jakub Czyz, Mohammad Karami 等USENIX Security 2016 · 被引用 149 次
- Hey, You Have a Problem: On the Feasibility of Large-Scale Web Vulnerability NotificationBen Stock, Giancarlo Pellegrino, Christian Rossow, Martin Johns 等USENIX Security 2016 · 被引用 130 次
- Surveylance: Automatically Detecting Online Survey ScamsAmin Kharraz, William K. Robertson, Engin KirdaS&P 2018 · 被引用 73 次
- Leaky Images: Targeted Privacy Attacks in the WebCristian-Alexandru Staicu, Michael PradelUSENIX Security 2019 · 被引用 21 次
相关 Paper
- TARDIS: Rolling Back The Clock On CMS-Targeting Cyber AttacksRanjita Pai Kasturi, Yiting Sun, Ruian Duan, Omar Alrawi 等S&P 2020 · 被引用 14 次
- From Payload to Plugin: Web-Scale Ecosystem Attribution of JavaScript Injection CampaignsRavindu De Silva, Nicholas Shao, Yigitcan Kaya, Mingxuan Yao 等CCS 2026
- In the DOM We Trust: Exploring the Hidden Dangers of Reading from the DOM on the WebJan Drescher, Sepehr Mirzaei, Soheil Khodayari, David Klein 等CCS 2025
- UntrustIDE: Exploiting Weaknesses in VS Code ExtensionsElizabeth Lin, Igibek Koishybayev, Trevor Dunlap, William Enck 等NDSS 2024
- An Empirical Study of Malicious Code In PyPI EcosystemWenbo Guo, Zhengzi Xu, Chengwei Liu, Cheng Huang 等ASE 2023 · 被引用 31 次
