有人買下 30 個 WordPress 外掛並埋入後門,8 個月後引爆 episode artwork

EPISODE · Apr 26, 2026 · 6 MIN

有人買下 30 個 WordPress 外掛並埋入後門,8 個月後引爆

from 脈報 · host 思思主播

有人花六位數買下 30 個 WordPress 外掛,後門靜待 8 個月後引爆,波及數十萬個網站。解析惡意程式如何繞過站長視線、為何強制更新不代表清乾淨,以及你現在應該做什麼。 ⭐ 文章深度讀:整理了確認 wp-config.php 是否中招的自檢方法,以及 31 個受影響外掛清單 → https://heymaibao.com/wordpress-plugin-backdoor-supply-chain-attack/ ⚡ 章節重點 合法收購,引爆數十萬網站的起點 00:00 神秘買家如何拿下 30 個外掛 01:08 後門設計:為何潛伏 8 個月都沒人發現 02:25 確認中招:檢查你的 wp-config.php 03:55 WordPress 信任漏洞,2017 年就有人用過 05:17 📝 懶人包 ∙ 攻擊者合法收購外掛組合後,第一個程式更新就是後門,這筆交易直接換來數十萬個 WordPress 網站的控制權 ∙ 後門只對搜尋引擎機器人 (Googlebot) 顯示垃圾連結,站長用自己的瀏覽器根本看不出來,惡意程式靜伏了 8 個月沒人察覺 ∙ WordPress.org 沒有外掛所有權移轉審查機制,這套攻擊劇本 9 年前就執行過一次,平台機制從未改變 ∙ 我的觀察:WordPress 外掛的「信任」是歷史積累出來的,不是即時驗證的。一旦外掛換了主人,那份信任就跟著轉移了,使用者毫無感知。安裝量排名、多年在 WordPress.org 上架,這些都不能當成現在的安全保證。 📚 參考資料 Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them (Austin Ginder,Anchor Hosting) → https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/ Millions of WordPress sites just got hacked… again (Code Report / NetworkChuck) → https://www.youtube.com/watch?v=piah4fV_o2Q

Episode metadata supplied by the publisher feed · Published Apr 26, 2026

Embed this episode

NOW PLAYING

有人買下 30 個 WordPress 外掛並埋入後門,8 個月後引爆

0:00 6:57

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of 脈報?

This episode is 6 minutes long.

When was this 脈報 episode published?

This episode was published on April 26, 2026.

Can I download this 脈報 episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!