Dormant Magento Supply Chain Attack Hits Up to 1,000 Merchants
May 28, 2025
21 extensions from Tigren, Magesolution, and Meetanshi carried six-year-old card-stealing malware—audit your plugins for the fake license and strengthen runtime protections.
Researchers at Sansec uncovered a supply chain attack infecting 21 Magento extensions from Tigren, Magesolution (MGS), and Meetanshi—malware that lay dormant for six years but activated last month—impacting an estimated 500–1,000 online merchants. The JavaScript payload runs in visitors’ browsers to steal payment card and other sensitive data in real time. If you operate e-commerce sites on Magento, audit your extensions for the fake license identified by Sansec, verify plugin integrity, and deploy runtime protections to detect malicious behavior.
Source:
Sansec research report

SAP has issued an emergency patch for CVE-2025-31324 (CVSS 10.0) in NetWeaver Visual Composer Framework 7.50 after ReliaQuest researchers observed active exploitation of a missing authorization check in the Metadata Uploader. This flaw allowed unauthenticated attackers to upload malicious binaries, jeopardizing system confidentiality, integrity, and availability. Organizations should immediately apply the update via the SAP Software Download Center and audit their systems for indicators of compromise; contact us for assistance with patch deployment and verification. (Source: SAP security advisory; contact us for more information.)

We are thrilled to announce the acquisition of Cavalry Solutions, a pioneer in managed services and operational technology (OT). This strategic acquisition enhances our capabilities in integrating IT and OT solutions, positioning us to meet the growing needs of interconnected technology systems across various industries.