The Backdoor Came Through the Plugin Repo, Not Around It
A hardcoded backdoor reached version 10.8.7 of a 20,000-install WordPress plugin via a compromised developer account. It was caught in under two hours and never distributed. What it did, why the detection matters more than the damage, and what it says about trusting the repo.