216.73.217.22

Okendo Reviews Supply Chain Attack

· Published 18/06/2026 17:00

Export JSON

Essential information

Published
18/06/2026 17:00
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
clickfix javascript injection netsupport netsupport rat okendo reviews remcos sectop rat smartapesg smartrat stealc supply chain attack
Related entities
3 indicators, 3 observables, 1 intrusion sets (apt), 18 techniques (mitre), 5 malware

Description

On May 14, 2026, a was discovered targeting the Okendo Reviews widget, a customer review platform used by over 18,000 brands. The threat actor injected malicious JavaScript code into the legitimate widget, which is deployed on high-traffic e-commerce pages including storefronts and product pages. The compromised JavaScript acted as a staged loader, using obfuscation, localStorage tracking, User-Agent filtering, and XOR-based decoding to conceal next-stage infrastructure. The attack employed -style social engineering to deceive users into executing malicious commands, ultimately delivering remote access trojans like and , or information stealers such as . Affected websites received hundreds of thousands to millions of monthly visitors, with nearly 15,000 blocks recorded in a single day.

External references