{"id":38291,"date":"2024-06-26T10:53:17","date_gmt":"2024-06-26T09:53:17","guid":{"rendered":"https:\/\/quike.it\/es\/?p=38291"},"modified":"2024-06-26T10:53:18","modified_gmt":"2024-06-26T09:53:18","slug":"ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org","status":"publish","type":"post","link":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/","title":{"rendered":"Ataque a cadena de Suministro en plugins de WordPress.org"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"38291\" class=\"elementor elementor-38291\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-1c0ef56 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"1c0ef56\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0609400\" data-id=\"0609400\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3d97ab3 elementor-widget elementor-widget-text-editor\" data-id=\"3d97ab3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Se ha detectado un nuevo <strong>Ataque de Cadena de Suministro (<a href=\"https:\/\/es.wikipedia.org\/wiki\/Ataque_a_cadena_de_suministro\" target=\"_blank\" rel=\"noopener\"><em>supply chain attack<\/em><\/a>)<\/strong> en el que un actor malicioso modific\u00f3 el <a href=\"https:\/\/es.wikipedia.org\/wiki\/C%C3%B3digo_fuente\" target=\"_blank\" rel=\"noopener\"><strong>c\u00f3digo fuente<\/strong><\/a> de al menos cinco plugins alojados en <strong>WordPress.org<\/strong> para incluir <a href=\"https:\/\/es.wikipedia.org\/wiki\/Script\" target=\"_blank\" rel=\"noopener\"><em><strong>scripts<\/strong><\/em><\/a> <a href=\"https:\/\/es.wikipedia.org\/wiki\/PHP\" target=\"_blank\" rel=\"noopener\"><strong>PHP<\/strong><\/a> maliciosos que crean nuevas cuentas con <strong><em>privilegios<\/em> <em>administrativos<\/em><\/strong> en los <strong>sitios web<\/strong> que los ejecutan.<\/p><p>El <strong>Ataque de Cadena de Suministro<\/strong> (<a href=\"https:\/\/es.wikipedia.org\/wiki\/Ataque_a_cadena_de_suministro\" target=\"_blank\" rel=\"noopener\"><em><strong>supply chain attack<\/strong><\/em><\/a>) fue descubierto ayer por el <a href=\"https:\/\/wordpress.org\/support\/topic\/a-security-message-from-the-plugin-review-team\/\" target=\"_blank\" rel=\"noopener\"><strong>WordPress.org Plugin Review Team<\/strong><\/a>, pero las inyecciones maliciosas parecen haber ocurrido hacia finales de la semana pasada, <strong><em>entre el 21 y el 22 de junio<\/em><\/strong>.<\/p><p>Tan pronto como <strong>Wordfence<\/strong> descubri\u00f3 la brecha, la compa\u00f1\u00eda notific\u00f3 a los desarrolladores de los <strong>plugins,<\/strong> lo que result\u00f3 en la <strong><em>publicaci\u00f3n de parches ayer<\/em><\/strong> para la mayor\u00eda de los productos.<\/p><p>En conjunto, los cinco <strong>plugins<\/strong> han sido instalados en m\u00e1s de <strong>35,000 sitios web<\/strong>:<\/p><ul><li><span style=\"color: #800000;\"><strong>Social Warfare 4.4.6.4 a 4.4.7.1<\/strong><\/span> (<em>arreglado en la <strong>versi\u00f3n 4.4.7.3<\/strong><\/em>)<\/li><li><span style=\"color: #800000;\"><strong>Blaze Widget 2.2.5 a 2.5.2<\/strong><\/span> (<em>arreglado en la <strong>versi\u00f3n 2.5.4<\/strong><\/em>)<\/li><li><span style=\"color: #800000;\"><strong>\u00a0Wrapper Link Element 1.0.2 a 1.0.3<\/strong><\/span> (<em>arreglado en la <strong>versi\u00f3n 1.0.5<\/strong><\/em>)<\/li><li><span style=\"color: #800000;\"><strong>Contact Form 7 Multi-Step Addon 1.0.4 a 1.0.5<\/strong><\/span> (<em>arreglado en la <strong>versi\u00f3n 1.0.7<\/strong><\/em>)<\/li><li><span style=\"color: #800000;\"><strong>Simply Show Hooks 1.2.1 a 1.2.2<\/strong><\/span> (<em>a\u00fan no hay arreglo disponible<\/em>)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e95e578 elementor-widget elementor-widget-text-editor\" data-id=\"e95e578\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p><a href=\"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/several-wordpressorg-plugins-various-versions-injected-backdoor\" target=\"_blank\" rel=\"noopener\"><strong>Wordfence se\u00f1ala<\/strong><\/a> que no sabe c\u00f3mo el actor malicioso logr\u00f3 acceder al <a href=\"https:\/\/es.wikipedia.org\/wiki\/C%C3%B3digo_fuente\" target=\"_blank\" rel=\"noopener\"><strong>c\u00f3digo fuente<\/strong><\/a> de los <strong>plugins,<\/strong> pero se est\u00e1 llevando a cabo una investigaci\u00f3n al respecto.<\/p><p>Aunque es posible que este <strong>Ataque de Cadena de Suministro<\/strong> afecte a un mayor n\u00famero de <strong>plugins de WordPress<\/strong>, la evidencia actual sugiere que la vulnerabilidad est\u00e1 limitada al conjunto mencionado de <strong>cinco plugins<\/strong>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-83503e9 elementor-grid-1 elementor-grid-tablet-2 elementor-grid-mobile-1 elementor-widget elementor-widget-loop-grid\" data-id=\"83503e9\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;template_id&quot;:&quot;30519&quot;,&quot;columns&quot;:1,&quot;_skin&quot;:&quot;post&quot;,&quot;columns_tablet&quot;:&quot;2&quot;,&quot;columns_mobile&quot;:&quot;1&quot;,&quot;edit_handle_selector&quot;:&quot;[data-elementor-type=\\&quot;loop-item\\&quot;]&quot;,&quot;row_gap&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;row_gap_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;row_gap_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"loop-grid.post\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-loop-container elementor-grid\" role=\"list\">\n\t\t<style id=\"loop-30519\">.elementor-30519 .elementor-element.elementor-element-98493d2 .elementor-column-gap-custom .elementor-column > .elementor-element-populated{padding:2px;}.elementor-30519 .elementor-element.elementor-element-ccee508 > .elementor-widget-wrap > .elementor-widget:not(.elementor-widget__width-auto):not(.elementor-widget__width-initial):not(:last-child):not(.elementor-absolute){--kit-widget-spacing:1px;}.elementor-widget-image .widget-image-caption{font-family:var( --e-global-typography-text-font-family ), Sans-serif;font-weight:var( --e-global-typography-text-font-weight );}.elementor-30519 .elementor-element.elementor-element-80149f2 img{height:85px;object-fit:cover;object-position:center center;}.elementor-30519 .elementor-element.elementor-element-80149f2:not( .elementor-widget-image ), .elementor-30519 .elementor-element.elementor-element-80149f2.elementor-widget-image img{-webkit-mask-image:url( https:\/\/quike.it\/es\/wp-content\/plugins\/elementor\/assets\/mask-shapes\/circle.svg );-webkit-mask-size:contain;-webkit-mask-position:center center;-webkit-mask-repeat:no-repeat;}.elementor-30519 .elementor-element.elementor-element-2109b1e > .elementor-widget-wrap > .elementor-widget:not(.elementor-widget__width-auto):not(.elementor-widget__width-initial):not(:last-child):not(.elementor-absolute){--kit-widget-spacing:3px;}.elementor-widget-post-info .elementor-icon-list-item{font-family:var( --e-global-typography-text-font-family ), Sans-serif;font-weight:var( --e-global-typography-text-font-weight );}.elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-icon{width:17px;}.elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-icon i{font-size:17px;}.elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-icon svg{--e-icon-list-icon-size:17px;}body:not(.rtl) .elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-text{padding-left:5px;}body.rtl .elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-text{padding-right:5px;}.elementor-30519 .elementor-element.elementor-element-26a68f7 .elementor-icon-list-item{font-family:\"Work Sans\", Sans-serif;font-weight:600;text-transform:uppercase;word-spacing:0px;}.elementor-30519 .elementor-element.elementor-element-26a68f7{width:100%;max-width:100%;align-self:center;}.elementor-widget-heading .elementor-heading-title{font-family:var( --e-global-typography-primary-font-family ), Sans-serif;font-weight:var( --e-global-typography-primary-font-weight );}.elementor-30519 .elementor-element.elementor-element-1ed9e84 .elementor-heading-title{font-family:\"Roboto\", Sans-serif;font-weight:600;color:#000000;}.elementor-widget-icon-list .elementor-icon-list-item > .elementor-icon-list-text, .elementor-widget-icon-list .elementor-icon-list-item > a{font-family:var( --e-global-typography-text-font-family ), Sans-serif;font-weight:var( --e-global-typography-text-font-weight );}.elementor-30519 .elementor-element.elementor-element-714486b .elementor-icon-list-icon i{color:#000000;transition:color 0.3s;}.elementor-30519 .elementor-element.elementor-element-714486b .elementor-icon-list-icon svg{fill:#000000;transition:fill 0.3s;}.elementor-30519 .elementor-element.elementor-element-714486b{--e-icon-list-icon-size:13px;--e-icon-list-icon-align:left;--e-icon-list-icon-margin:0 calc(var(--e-icon-list-icon-size, 1em) * 0.25) 0 0;--icon-vertical-align:center;--icon-vertical-offset:0px;margin:0px 0px calc(var(--kit-widget-spacing, 0px) + 0px) 0px;padding:0px 0px 0px 0px;width:100%;max-width:100%;}.elementor-30519 .elementor-element.elementor-element-714486b .elementor-icon-list-item > .elementor-icon-list-text, .elementor-30519 .elementor-element.elementor-element-714486b .elementor-icon-list-item > a{font-family:\"Work Sans\", Sans-serif;font-size:11px;font-weight:500;text-transform:capitalize;line-height:16px;letter-spacing:1px;}.elementor-30519 .elementor-element.elementor-element-714486b .elementor-icon-list-text{color:#333333;transition:color 0.3s;}.elementor-30519 .elementor-element.elementor-element-0a32de7 .elementor-icon-list-icon i{color:#000000;transition:color 0.3s;}.elementor-30519 .elementor-element.elementor-element-0a32de7 .elementor-icon-list-icon svg{fill:#000000;transition:fill 0.3s;}.elementor-30519 .elementor-element.elementor-element-0a32de7{--e-icon-list-icon-size:13px;--e-icon-list-icon-align:left;--e-icon-list-icon-margin:0 calc(var(--e-icon-list-icon-size, 1em) * 0.25) 0 0;--icon-vertical-align:center;--icon-vertical-offset:0px;margin:0px 0px calc(var(--kit-widget-spacing, 0px) + 0px) 0px;padding:0px 0px 0px 0px;width:100%;max-width:100%;}.elementor-30519 .elementor-element.elementor-element-0a32de7 .elementor-icon-list-item > .elementor-icon-list-text, .elementor-30519 .elementor-element.elementor-element-0a32de7 .elementor-icon-list-item > a{font-family:\"Work Sans\", Sans-serif;font-size:11px;font-weight:500;text-transform:capitalize;line-height:16px;letter-spacing:1px;}.elementor-30519 .elementor-element.elementor-element-0a32de7 .elementor-icon-list-text{color:#333333;transition:color 0.3s;}@media(min-width:768px){.elementor-30519 .elementor-element.elementor-element-ccee508{width:20%;}.elementor-30519 .elementor-element.elementor-element-2109b1e{width:79.997%;}}@media(max-width:767px){.elementor-30519 .elementor-element.elementor-element-98493d2 .elementor-column-gap-custom .elementor-column > .elementor-element-populated{padding:2px;}.elementor-30519 .elementor-element.elementor-element-ccee508{width:25%;}.elementor-30519 .elementor-element.elementor-element-2109b1e{width:75%;}.elementor-30519 .elementor-element.elementor-element-1ed9e84 .elementor-heading-title{font-size:15px;}}<\/style>\t\t<div data-elementor-type=\"loop-item\" data-elementor-id=\"30519\" class=\"elementor elementor-30519 e-loop-item e-loop-item-36959 post-36959 post type-post status-publish format-standard has-post-thumbnail hentry category-seguridad category-wordpress\" data-elementor-post-type=\"elementor_library\" data-custom-edit-handle=\"1\">\n\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-98493d2 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"98493d2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-custom\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-ccee508\" data-id=\"ccee508\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-80149f2 elementor-widget elementor-widget-image\" data-id=\"80149f2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/\" target=\"_blank\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1120\" height=\"600\" src=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png\" class=\"attachment-full size-full wp-image-35403\" alt=\"\" srcset=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png 1120w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-300x161.png 300w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-1024x549.png 1024w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-768x411.png 768w\" sizes=\"(max-width: 1120px) 100vw, 1120px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-2109b1e\" data-id=\"2109b1e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-26a68f7 elementor-align-left elementor-widget__width-inherit elementor-widget elementor-widget-post-info\" data-id=\"26a68f7\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"categorias-post\" data-widget_type=\"post-info.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-inline-items elementor-icon-list-items elementor-post-info\">\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-repeater-item-dfd774d elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-custom\">\n\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/category\/informatica\/seguridad\/\" rel=\"tag\">Seguridad<\/a> <a href=\"https:\/\/quike.it\/es\/category\/web\/wordpress\/\" rel=\"tag\">WordPress<\/a>\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ed9e84 elementor-widget elementor-widget-heading\" data-id=\"1ed9e84\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"top-post\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\"><a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/\" target=\"_blank\">Falla Cr\u00edtica en LayerSlider de WordPress<\/a><\/div>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-714486b elementor-icon-list--layout-inline elementor-align-start elementor-hidden-tablet elementor-hidden-mobile elementor-widget__width-inherit elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"714486b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/\">\n\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-book-reader\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M352 96c0-53.02-42.98-96-96-96s-96 42.98-96 96 42.98 96 96 96 96-42.98 96-96zM233.59 241.1c-59.33-36.32-155.43-46.3-203.79-49.05C13.55 191.13 0 203.51 0 219.14v222.8c0 14.33 11.59 26.28 26.49 27.05 43.66 2.29 131.99 10.68 193.04 41.43 9.37 4.72 20.48-1.71 20.48-11.87V252.56c-.01-4.67-2.32-8.95-6.42-11.46zm248.61-49.05c-48.35 2.74-144.46 12.73-203.78 49.05-4.1 2.51-6.41 6.96-6.41 11.63v245.79c0 10.19 11.14 16.63 20.54 11.9 61.04-30.72 149.32-39.11 192.97-41.4 14.9-.78 26.49-12.73 26.49-27.06V219.14c-.01-15.63-13.56-28.01-29.81-27.09z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">75 lecturas<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-comments\" viewBox=\"0 0 576 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 192c0-88.4-93.1-160-208-160S0 103.6 0 192c0 34.3 14.1 65.9 38 92-13.4 30.2-35.5 54.2-35.8 54.5-2.2 2.3-2.8 5.7-1.5 8.7S4.8 352 8 352c36.6 0 66.9-12.3 88.7-25 32.2 15.7 70.3 25 111.3 25 114.9 0 208-71.6 208-160zm122 220c23.9-26 38-57.7 38-92 0-66.9-53.5-124.2-129.3-148.1.9 6.6 1.3 13.3 1.3 20.1 0 105.9-107.7 192-240 192-10.8 0-21.3-.8-31.7-1.9C207.8 439.6 281.8 480 368 480c41 0 79.1-9.2 111.3-25 21.8 12.7 52.1 25 88.7 25 3.2 0 6.1-1.9 7.3-4.8 1.3-2.9.7-6.3-1.5-8.7-.3-.3-22.4-24.2-35.8-54.5z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/#respond\">sin comentarios<\/a><\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0a32de7 elementor-icon-list--layout-inline elementor-align-start elementor-widget__width-inherit elementor-hidden-desktop elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"0a32de7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/\">\n\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-book-reader\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M352 96c0-53.02-42.98-96-96-96s-96 42.98-96 96 42.98 96 96 96 96-42.98 96-96zM233.59 241.1c-59.33-36.32-155.43-46.3-203.79-49.05C13.55 191.13 0 203.51 0 219.14v222.8c0 14.33 11.59 26.28 26.49 27.05 43.66 2.29 131.99 10.68 193.04 41.43 9.37 4.72 20.48-1.71 20.48-11.87V252.56c-.01-4.67-2.32-8.95-6.42-11.46zm248.61-49.05c-48.35 2.74-144.46 12.73-203.78 49.05-4.1 2.51-6.41 6.96-6.41 11.63v245.79c0 10.19 11.14 16.63 20.54 11.9 61.04-30.72 149.32-39.11 192.97-41.4 14.9-.78 26.49-12.73 26.49-27.06V219.14c-.01-15.63-13.56-28.01-29.81-27.09z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">75 lecturas<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-comments\" viewBox=\"0 0 576 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 192c0-88.4-93.1-160-208-160S0 103.6 0 192c0 34.3 14.1 65.9 38 92-13.4 30.2-35.5 54.2-35.8 54.5-2.2 2.3-2.8 5.7-1.5 8.7S4.8 352 8 352c36.6 0 66.9-12.3 88.7-25 32.2 15.7 70.3 25 111.3 25 114.9 0 208-71.6 208-160zm122 220c23.9-26 38-57.7 38-92 0-66.9-53.5-124.2-129.3-148.1.9 6.6 1.3 13.3 1.3 20.1 0 105.9-107.7 192-240 192-10.8 0-21.3-.8-31.7-1.9C207.8 439.6 281.8 480 368 480c41 0 79.1-9.2 111.3-25 21.8 12.7 52.1 25 88.7 25 3.2 0 6.1-1.9 7.3-4.8 1.3-2.9.7-6.3-1.5-8.7-.3-.3-22.4-24.2-35.8-54.5z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/quike.it\/es\/falla-critica-en-layerslider-de-wordpress\/#respond\">0<\/a><\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e610fa7 elementor-widget elementor-widget-heading\" data-id=\"e610fa7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Operaci\u00f3n de puerta trasera e indicadores de compromiso (IoCs)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dc78324 elementor-widget elementor-widget-image\" data-id=\"dc78324\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280.jpg\" data-elementor-open-lightbox=\"yes\" data-elementor-lightbox-title=\"backdoor\" data-e-action-hash=\"#elementor-action%3Aaction%3Dlightbox%26settings%3DeyJpZCI6MzgyOTgsInVybCI6Imh0dHBzOlwvXC9xdWlrZS5pdFwvZXNcL3dwLWNvbnRlbnRcL3VwbG9hZHNcL3NpdGVzXC8zXC8yMDI0XC8wNlwvc2VjdXJpdHktNzA1NzU2MF8xMjgwLmpwZyJ9\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"1280\" height=\"667\" src=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280.jpg\" class=\"attachment-full size-full wp-image-38298\" alt=\"ataque a cadena de suministro\" srcset=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280.jpg 1280w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280-300x156.jpg 300w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280-1024x534.jpg 1024w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/06\/security-7057560_1280-768x400.jpg 768w\" sizes=\"(max-width: 1280px) 100vw, 1280px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-62af417 elementor-widget elementor-widget-text-editor\" data-id=\"62af417\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>El <strong>c\u00f3digo malicioso<\/strong> en los <strong>plugins<\/strong> infectados intenta crear nuevas <strong><em>cuentas de administrador<\/em><\/strong> e inyectar <a href=\"https:\/\/quike.it\/es\/spam-la-lucha-contra-el-correo-no-deseado\/\" target=\"_blank\" rel=\"noopener\"><strong>spam<\/strong><\/a> de <a href=\"https:\/\/es.wikipedia.org\/wiki\/Posicionamiento_en_buscadores\" target=\"_blank\" rel=\"noopener\"><strong>SEO<\/strong><\/a> en el <strong>sitio web<\/strong> comprometido.<\/p><p>\u00ab<strong>En esta etapa, sabemos que el malware inyectado intenta crear una nueva cuenta de usuario administrativo y luego env\u00eda esos detalles al servidor controlado por el atacante<\/strong>\u00ab, <a href=\"https:\/\/www.wordfence.com\/blog\/2024\/06\/supply-chain-attack-on-wordpress-org-plugins-leads-to-5-maliciously-compromised-wordpress-plugins\/\" target=\"_blank\" rel=\"noopener\"><strong>explica Wordfence<\/strong><\/a>.<\/p><p>\u00ab<em><strong>Adem\u00e1s, parece que el actor de la amenaza tambi\u00e9n inyect\u00f3 JavaScript malicioso en el pie de p\u00e1gina de los sitios web que parece agregar spam de SEO en todo el sitio web<\/strong><\/em>\u00ab.<\/p><p>Los datos se transmiten a la <a href=\"https:\/\/quike.it\/es\/como-se-asigna-la-ip-publica-cuando-nos-conectamos-a-internet\/\" target=\"_blank\" rel=\"noopener\"><strong>direcci\u00f3n IP<\/strong><\/a> <strong>94.156.79[.]8<\/strong>, mientras que las cuentas de administrador creadas arbitrariamente se nombran <em><strong>\u00abOptions\u00bb<\/strong><\/em> y <em><strong>\u00abPluginAuth\u00bb,<\/strong> <a href=\"https:\/\/www.wordfence.com\/blog\/2024\/06\/supply-chain-attack-on-wordpress-org-plugins-leads-to-5-maliciously-compromised-wordpress-plugins\/\" target=\"_blank\" rel=\"noopener\"><strong>dicen los investigadores<\/strong><\/a><\/em>.<\/p><p>Los propietarios de<strong> sitios web<\/strong> que noten tales cuentas o tr\u00e1fico a la <a href=\"https:\/\/quike.it\/es\/que-es-un-ip-estatico-y-a-que-sirve\/\" target=\"_blank\" rel=\"noopener\"><strong>direcci\u00f3n IP<\/strong><\/a> del atacante deben realizar un escaneo completo de <a href=\"https:\/\/quike.it\/es\/como-eliminar-malware-de-tu-computadora\/\" target=\"_blank\" rel=\"noopener\"><strong>malware<\/strong><\/a> y una limpieza.<\/p><p>\u00ab<em><strong>Si tienes alguno de estos plugins instalados, debes considerar tu instalaci\u00f3n comprometida e inmediatamente entrar en modo de respuesta a incidentes.<\/strong><\/em>\u00bb \u2013 <a href=\"https:\/\/www.wordfence.com\/blog\/2024\/06\/supply-chain-attack-on-wordpress-org-plugins-leads-to-5-maliciously-compromised-wordpress-plugins\/\" target=\"_blank\" rel=\"noopener\"><strong>Wordfence.<\/strong><\/a><\/p><p><a href=\"https:\/\/www.wordfence.com\/blog\/2024\/06\/supply-chain-attack-on-wordpress-org-plugins-leads-to-5-maliciously-compromised-wordpress-plugins\/\" target=\"_blank\" rel=\"noopener\"><strong>Wordfence se\u00f1ala<\/strong><\/a> que algunos de los <strong>plugins<\/strong> afectados fueron temporalmente eliminados de <strong>WordPress.org,<\/strong> lo que puede resultar en advertencias para los usuarios, incluso si utilizan una versi\u00f3n parcheada.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-101dc6e elementor-grid-1 elementor-grid-tablet-2 elementor-grid-mobile-1 elementor-widget elementor-widget-loop-grid\" data-id=\"101dc6e\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;template_id&quot;:&quot;30519&quot;,&quot;columns&quot;:1,&quot;_skin&quot;:&quot;post&quot;,&quot;columns_tablet&quot;:&quot;2&quot;,&quot;columns_mobile&quot;:&quot;1&quot;,&quot;edit_handle_selector&quot;:&quot;[data-elementor-type=\\&quot;loop-item\\&quot;]&quot;,&quot;row_gap&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;row_gap_tablet&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]},&quot;row_gap_mobile&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:[]}}\" data-widget_type=\"loop-grid.post\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-loop-container elementor-grid\" role=\"list\">\n\t\t\t\t<div data-elementor-type=\"loop-item\" data-elementor-id=\"30519\" class=\"elementor elementor-30519 e-loop-item e-loop-item-36185 post-36185 post type-post status-publish format-standard has-post-thumbnail hentry category-seguridad category-wordpress\" data-elementor-post-type=\"elementor_library\" data-custom-edit-handle=\"1\">\n\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-98493d2 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"98493d2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-custom\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-ccee508\" data-id=\"ccee508\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-80149f2 elementor-widget elementor-widget-image\" data-id=\"80149f2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/\" target=\"_blank\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"1120\" height=\"600\" src=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png\" class=\"attachment-full size-full wp-image-35403\" alt=\"\" srcset=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png 1120w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-300x161.png 300w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-1024x549.png 1024w, https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert-768x411.png 768w\" sizes=\"(max-width: 1120px) 100vw, 1120px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-2109b1e\" data-id=\"2109b1e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-26a68f7 elementor-align-left elementor-widget__width-inherit elementor-widget elementor-widget-post-info\" data-id=\"26a68f7\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"categorias-post\" data-widget_type=\"post-info.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-inline-items elementor-icon-list-items elementor-post-info\">\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-repeater-item-dfd774d elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-custom\">\n\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/category\/informatica\/seguridad\/\" rel=\"tag\">Seguridad<\/a> <a href=\"https:\/\/quike.it\/es\/category\/web\/wordpress\/\" rel=\"tag\">WordPress<\/a>\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ed9e84 elementor-widget elementor-widget-heading\" data-id=\"1ed9e84\" data-element_type=\"widget\" data-e-type=\"widget\" id=\"top-post\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<div class=\"elementor-heading-title elementor-size-default\"><a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/\" target=\"_blank\">Malware Evasive Sign1 ataca 39,000 sitios de WordPress<\/a><\/div>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-714486b elementor-icon-list--layout-inline elementor-align-start elementor-hidden-tablet elementor-hidden-mobile elementor-widget__width-inherit elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"714486b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/\">\n\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-book-reader\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M352 96c0-53.02-42.98-96-96-96s-96 42.98-96 96 42.98 96 96 96 96-42.98 96-96zM233.59 241.1c-59.33-36.32-155.43-46.3-203.79-49.05C13.55 191.13 0 203.51 0 219.14v222.8c0 14.33 11.59 26.28 26.49 27.05 43.66 2.29 131.99 10.68 193.04 41.43 9.37 4.72 20.48-1.71 20.48-11.87V252.56c-.01-4.67-2.32-8.95-6.42-11.46zm248.61-49.05c-48.35 2.74-144.46 12.73-203.78 49.05-4.1 2.51-6.41 6.96-6.41 11.63v245.79c0 10.19 11.14 16.63 20.54 11.9 61.04-30.72 149.32-39.11 192.97-41.4 14.9-.78 26.49-12.73 26.49-27.06V219.14c-.01-15.63-13.56-28.01-29.81-27.09z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">84 lecturas<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-comments\" viewBox=\"0 0 576 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 192c0-88.4-93.1-160-208-160S0 103.6 0 192c0 34.3 14.1 65.9 38 92-13.4 30.2-35.5 54.2-35.8 54.5-2.2 2.3-2.8 5.7-1.5 8.7S4.8 352 8 352c36.6 0 66.9-12.3 88.7-25 32.2 15.7 70.3 25 111.3 25 114.9 0 208-71.6 208-160zm122 220c23.9-26 38-57.7 38-92 0-66.9-53.5-124.2-129.3-148.1.9 6.6 1.3 13.3 1.3 20.1 0 105.9-107.7 192-240 192-10.8 0-21.3-.8-31.7-1.9C207.8 439.6 281.8 480 368 480c41 0 79.1-9.2 111.3-25 21.8 12.7 52.1 25 88.7 25 3.2 0 6.1-1.9 7.3-4.8 1.3-2.9.7-6.3-1.5-8.7-.3-.3-22.4-24.2-35.8-54.5z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/#respond\">sin comentarios<\/a><\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0a32de7 elementor-icon-list--layout-inline elementor-align-start elementor-widget__width-inherit elementor-hidden-desktop elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list\" data-id=\"0a32de7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"icon-list.default\">\n\t\t\t\t\t\t\t<ul class=\"elementor-icon-list-items elementor-inline-items\">\n\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/\">\n\n\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-book-reader\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M352 96c0-53.02-42.98-96-96-96s-96 42.98-96 96 42.98 96 96 96 96-42.98 96-96zM233.59 241.1c-59.33-36.32-155.43-46.3-203.79-49.05C13.55 191.13 0 203.51 0 219.14v222.8c0 14.33 11.59 26.28 26.49 27.05 43.66 2.29 131.99 10.68 193.04 41.43 9.37 4.72 20.48-1.71 20.48-11.87V252.56c-.01-4.67-2.32-8.95-6.42-11.46zm248.61-49.05c-48.35 2.74-144.46 12.73-203.78 49.05-4.1 2.51-6.41 6.96-6.41 11.63v245.79c0 10.19 11.14 16.63 20.54 11.9 61.04-30.72 149.32-39.11 192.97-41.4 14.9-.78 26.49-12.73 26.49-27.06V219.14c-.01-15.63-13.56-28.01-29.81-27.09z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\">84 lecturas<\/span>\n\t\t\t\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t\t\t<li class=\"elementor-icon-list-item elementor-inline-item\">\n\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-icon\">\n\t\t\t\t\t\t\t<svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-comments\" viewBox=\"0 0 576 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 192c0-88.4-93.1-160-208-160S0 103.6 0 192c0 34.3 14.1 65.9 38 92-13.4 30.2-35.5 54.2-35.8 54.5-2.2 2.3-2.8 5.7-1.5 8.7S4.8 352 8 352c36.6 0 66.9-12.3 88.7-25 32.2 15.7 70.3 25 111.3 25 114.9 0 208-71.6 208-160zm122 220c23.9-26 38-57.7 38-92 0-66.9-53.5-124.2-129.3-148.1.9 6.6 1.3 13.3 1.3 20.1 0 105.9-107.7 192-240 192-10.8 0-21.3-.8-31.7-1.9C207.8 439.6 281.8 480 368 480c41 0 79.1-9.2 111.3-25 21.8 12.7 52.1 25 88.7 25 3.2 0 6.1-1.9 7.3-4.8 1.3-2.9.7-6.3-1.5-8.7-.3-.3-22.4-24.2-35.8-54.5z\"><\/path><\/svg>\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-icon-list-text\"><a href=\"https:\/\/quike.it\/es\/malware-evasive-sign1-ataca-39000-sitios-de-wordpress\/#respond\">0<\/a><\/span>\n\t\t\t\t\t\t\t\t\t<\/li>\n\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Se ha detectado un nuevo Ataque de Cadena de Suministro (supply chain attack) en el que un actor malicioso modific\u00f3 el c\u00f3digo fuente de al menos cinco plugins alojados en WordPress.org para incluir scripts PHP maliciosos que crean nuevas cuentas con privilegios administrativos en los sitios web que los ejecutan. El Ataque de Cadena de [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":35403,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[89,45],"tags":[],"class_list":["post-38291","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguridad","category-wordpress"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Ataque a cadena de Suministro en plugins de Wordpress.org<\/title>\n<meta name=\"description\" content=\"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ataque a cadena de Suministro en plugins de Wordpress.org\" \/>\n<meta property=\"og:description\" content=\"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/\" \/>\n<meta property=\"og:site_name\" content=\"El BLOG de Enrique V\u00e1squez B.\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/zeven.sa.1\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/zeven.sa.1\" \/>\n<meta property=\"article:published_time\" content=\"2024-06-26T09:53:17+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-26T09:53:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1120\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Enrique V\u00e1squez B.\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@quike1974\" \/>\n<meta name=\"twitter:site\" content=\"@quike1974\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Enrique V\u00e1squez B.\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/\"},\"author\":{\"name\":\"Enrique V\u00e1squez B.\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#\\\/schema\\\/person\\\/e53c62e8ab2e3f878e77d3a617483cc8\"},\"headline\":\"Ataque a cadena de Suministro en plugins de WordPress.org\",\"datePublished\":\"2024-06-26T09:53:17+00:00\",\"dateModified\":\"2024-06-26T09:53:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/\"},\"wordCount\":466,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#\\\/schema\\\/person\\\/e53c62e8ab2e3f878e77d3a617483cc8\"},\"image\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2024\\\/02\\\/WordPress_Alert.png\",\"articleSection\":[\"Seguridad\",\"WordPress\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#respond\"]}]},{\"@type\":[\"WebPage\",\"ItemPage\"],\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/\",\"url\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/\",\"name\":\"Ataque a cadena de Suministro en plugins de Wordpress.org\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2024\\\/02\\\/WordPress_Alert.png\",\"datePublished\":\"2024-06-26T09:53:17+00:00\",\"dateModified\":\"2024-06-26T09:53:18+00:00\",\"description\":\"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#primaryimage\",\"url\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2024\\\/02\\\/WordPress_Alert.png\",\"contentUrl\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2024\\\/02\\\/WordPress_Alert.png\",\"width\":1120,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Inicio\",\"item\":\"https:\\\/\\\/quike.it\\\/es\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WEB\",\"item\":\"https:\\\/\\\/quike.it\\\/es\\\/category\\\/web\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"WordPress\",\"item\":\"https:\\\/\\\/quike.it\\\/es\\\/category\\\/web\\\/wordpress\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Ataque a cadena de Suministro en plugins de WordPress.org\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#website\",\"url\":\"https:\\\/\\\/quike.it\\\/es\\\/\",\"name\":\"El BLOG de Enrique V\u00e1squez B.\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#\\\/schema\\\/person\\\/e53c62e8ab2e3f878e77d3a617483cc8\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/quike.it\\\/es\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/#\\\/schema\\\/person\\\/e53c62e8ab2e3f878e77d3a617483cc8\",\"name\":\"Enrique V\u00e1squez B.\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/02\\\/me.png\",\"url\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/02\\\/me.png\",\"contentUrl\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/02\\\/me.png\",\"width\":512,\"height\":512,\"caption\":\"Enrique V\u00e1squez B.\"},\"logo\":{\"@id\":\"https:\\\/\\\/quike.it\\\/es\\\/wp-content\\\/uploads\\\/sites\\\/3\\\/2021\\\/02\\\/me.png\"},\"description\":\"Programador desde 1988, con pasi\u00f3n por escribir art\u00edculos de todo tipo. Actualmente desarrolla para ZEVEN S.A. el Sistema de Facturaci\u00f3n Electr\u00f3nica. Ecuatoriano de nacimiento e italiano de residencia, escribe desde G\u00e9nova, ciudad que ha llegado a amar tanto como su natal Guayaquil. Padre de dos hijos que son su orgullo y esposo de una mujer excepcional.\",\"sameAs\":[\"https:\\\/\\\/quike.it\",\"https:\\\/\\\/www.facebook.com\\\/zeven.sa.1\",\"https:\\\/\\\/www.instagram.com\\\/quikev1974\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carlos-enrique-vasquez-bautista-074893b\\\/\",\"https:\\\/\\\/x.com\\\/quike1974\"],\"url\":\"https:\\\/\\\/quike.it\\\/es\\\/author\\\/quike\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Ataque a cadena de Suministro en plugins de Wordpress.org","description":"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/","og_locale":"es_ES","og_type":"article","og_title":"Ataque a cadena de Suministro en plugins de Wordpress.org","og_description":"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...","og_url":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/","og_site_name":"El BLOG de Enrique V\u00e1squez B.","article_publisher":"https:\/\/www.facebook.com\/zeven.sa.1","article_author":"https:\/\/www.facebook.com\/zeven.sa.1","article_published_time":"2024-06-26T09:53:17+00:00","article_modified_time":"2024-06-26T09:53:18+00:00","og_image":[{"width":1120,"height":600,"url":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png","type":"image\/png"}],"author":"Enrique V\u00e1squez B.","twitter_card":"summary_large_image","twitter_creator":"@quike1974","twitter_site":"@quike1974","twitter_misc":{"Escrito por":"Enrique V\u00e1squez B.","Tiempo de lectura":"3 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#article","isPartOf":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/"},"author":{"name":"Enrique V\u00e1squez B.","@id":"https:\/\/quike.it\/es\/#\/schema\/person\/e53c62e8ab2e3f878e77d3a617483cc8"},"headline":"Ataque a cadena de Suministro en plugins de WordPress.org","datePublished":"2024-06-26T09:53:17+00:00","dateModified":"2024-06-26T09:53:18+00:00","mainEntityOfPage":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/"},"wordCount":466,"commentCount":0,"publisher":{"@id":"https:\/\/quike.it\/es\/#\/schema\/person\/e53c62e8ab2e3f878e77d3a617483cc8"},"image":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#primaryimage"},"thumbnailUrl":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png","articleSection":["Seguridad","WordPress"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#respond"]}]},{"@type":["WebPage","ItemPage"],"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/","url":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/","name":"Ataque a cadena de Suministro en plugins de Wordpress.org","isPartOf":{"@id":"https:\/\/quike.it\/es\/#website"},"primaryImageOfPage":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#primaryimage"},"image":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#primaryimage"},"thumbnailUrl":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png","datePublished":"2024-06-26T09:53:17+00:00","dateModified":"2024-06-26T09:53:18+00:00","description":"Aunque es posible que este Ataque de Cadena de Suministro afecte a un mayor n\u00famero de plugins de WordPress, la evidencia actual sugiere...","breadcrumb":{"@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#primaryimage","url":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png","contentUrl":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2024\/02\/WordPress_Alert.png","width":1120,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/quike.it\/es\/ataque-a-cadena-de-suministro-en-plugins-de-wordpress-org\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Inicio","item":"https:\/\/quike.it\/es\/"},{"@type":"ListItem","position":2,"name":"WEB","item":"https:\/\/quike.it\/es\/category\/web\/"},{"@type":"ListItem","position":3,"name":"WordPress","item":"https:\/\/quike.it\/es\/category\/web\/wordpress\/"},{"@type":"ListItem","position":4,"name":"Ataque a cadena de Suministro en plugins de WordPress.org"}]},{"@type":"WebSite","@id":"https:\/\/quike.it\/es\/#website","url":"https:\/\/quike.it\/es\/","name":"El BLOG de Enrique V\u00e1squez B.","description":"","publisher":{"@id":"https:\/\/quike.it\/es\/#\/schema\/person\/e53c62e8ab2e3f878e77d3a617483cc8"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/quike.it\/es\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":["Person","Organization"],"@id":"https:\/\/quike.it\/es\/#\/schema\/person\/e53c62e8ab2e3f878e77d3a617483cc8","name":"Enrique V\u00e1squez B.","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2021\/02\/me.png","url":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2021\/02\/me.png","contentUrl":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2021\/02\/me.png","width":512,"height":512,"caption":"Enrique V\u00e1squez B."},"logo":{"@id":"https:\/\/quike.it\/es\/wp-content\/uploads\/sites\/3\/2021\/02\/me.png"},"description":"Programador desde 1988, con pasi\u00f3n por escribir art\u00edculos de todo tipo. Actualmente desarrolla para ZEVEN S.A. el Sistema de Facturaci\u00f3n Electr\u00f3nica. Ecuatoriano de nacimiento e italiano de residencia, escribe desde G\u00e9nova, ciudad que ha llegado a amar tanto como su natal Guayaquil. Padre de dos hijos que son su orgullo y esposo de una mujer excepcional.","sameAs":["https:\/\/quike.it","https:\/\/www.facebook.com\/zeven.sa.1","https:\/\/www.instagram.com\/quikev1974","https:\/\/www.linkedin.com\/in\/carlos-enrique-vasquez-bautista-074893b\/","https:\/\/x.com\/quike1974"],"url":"https:\/\/quike.it\/es\/author\/quike\/"}]}},"_links":{"self":[{"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/posts\/38291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/comments?post=38291"}],"version-history":[{"count":23,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/posts\/38291\/revisions"}],"predecessor-version":[{"id":38316,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/posts\/38291\/revisions\/38316"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/media\/35403"}],"wp:attachment":[{"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/media?parent=38291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/categories?post=38291"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/quike.it\/es\/wp-json\/wp\/v2\/tags?post=38291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}