AI, ML, and networking — applied and examined.
Taking Down Tens of Thousands of Websites: Do Hackers Now Just Spend Money Instead of Writing Code?
Taking Down Tens of Thousands of Websites: Do Hackers Now Just Spend Money Instead of Writing Code?

Taking Down Tens of Thousands of Websites: Do Hackers Now Just Spend Money Instead of Writing Code?

Look at this foreign media illustration, a hacker in a hoodie mixed with code, absolutely brilliant

It’s a gorgeous sunny day in Shanghai today, with the temperature surprisingly hitting nearly 23 degrees Celsius. On a drowsy spring day like this, it’s the perfect time to chat about some spine-chilling tech gossip.

My take is this: in today’s coding world, the most terrifying hackers have long stopped grinding away at raw technical exploits. Instead, they’ve pivoted to mergers and acquisitions.

1. Too Tired to Find Vulnerabilities? Just Buy the City Gates

You might not have noticed, but just this month—April 2026—half the WordPress community was left completely stunned. Over 30 well-known WordPress plugins were urgently taken down by official channels. The reason was incredibly simple: backdoors were quietly injected into these plugins, turning tens of thousands of websites directly into zombies.

Honestly, I always thought hackers were those hardcore nerds wrapped in hoodies, frantically banging on keyboards in the middle of the night to find system vulnerabilities. But this time, it’s completely different. This attack method is highly commercialized—you could even say it’s extremely rich and capricious.

How did the hackers get into other people’s servers? They literally pulled out their wallets and bought the “keys to the city gates.”

Sounds absurd, right?

Here is the issue. Hackers astutely noticed that while many open-source plugins have massive user bases, their original creators are either getting too old to code or too busy with full-time jobs to maintain them. These plugins are like dilapidated city defenses that countless people still rely on. Consequently, hackers hopped onto legitimate trading platforms like Flippa and fully acquired these plugins—code, intellectual property, and all—at a price that satisfied everyone.

The original creators take the money and retire, and everyone is happy. As for the buyer—a mysterious figure named Chris, according to cybersecurity firms investigating the incident—they naturally gain top-level update permissions for these plugins.

What’s the first thing you do under new management? Hand out “perks” to the old users, of course. During a routine version update a few months later, the new boss conveniently slipped in some malicious code.

You thought you were updating to fix bugs, but in reality, you were actively opening the door and welcoming robbers into your home.

It’s impossible to defend against.

2. An 8-Month Undercover “Trust Scam”

This was by no means a spur-of-the-moment prank. What impressed me the most is that these hackers possess terrifying patience.

As far as I know, the acquisition deal likely took place around May 2025. After obtaining permissions, the new boss Chris didn’t strike immediately. He waited until August 8th before very restrainedly sneaking a remote code execution backdoor into his first version update.

What happened after the injection? Logically, you’d think it was time to wreak havoc.

It wasn’t that simple.

This backdoor entered a state of hibernation, lying completely dormant for 8 months without doing anything malicious. It wasn’t until around April 5, 2026, that it was suddenly awakened. Its very first act upon waking up was to tamper with the core WordPress wp-config.php file, and then frantically inject SEO spam links into tens of thousands of web pages.

If you’ve ever been a webmaster, you know exactly how disgusting these secretly injected SEO spam links are. On the surface, your website looks perfectly fine, but in the eyes of search engines, your site’s basement is packed full of illegal gambling and sketchy ads. Your website’s reputation will instantly plummet to zero.

It’s like hiring a city guard who diligently stands watch every day and even helps you catch a few thieves. Then, in the middle of the night eight months later, he suddenly throws the city gates wide open and loots your house.

Put simply, this is known as a supply chain attack.

People normally spend a fortune buying firewalls and deploying zero-trust networks to defend against frontal assaults from external enemies. But what if the locksmith who fixes your locks every day has secretly had his shop bought out by the mob? The more advanced your lock, the harder you fall. Last weekend, I chatted about this with a buddy in DevOps; he took a sip of beer and sighed heavily, saying that his hands tremble nowadays whenever they update dependency packages. You just never know who exactly is submitting the code on the other side of the screen.

3. Speaking of Undercover Agents, There Are Different Tiers

That being said, spending money to buy plugins and inject backdoors might sound flush with cash, but in the face of another legendary mastermind, it’s just nouveau riche behavior.

Since we’re on the subject, I have to digress a bit and mention the “XZ Utils Backdoor Incident” that shocked the entire tech world in 2024. If the WordPress buyer bought trust with money, then the protagonist of the XZ incident, Jia Tan, is an absolute “Oscar-winning undercover actor.”

Truly ruthless.

To place a backdoor in XZ Utils, Jia Tan laid low for a full two years. What is XZ Utils? It’s a low-level compression tool used by almost every Linux system. Compromising it is the equivalent of acquiring the server keys to half the internet.

How did Jia Tan pull it off? He didn’t use money to buy his way in; he used time to grind it out. First, he frantically submitted high-quality code to the project, helped fix various complex bugs, and answered every question the community had. The original creator, Lasse Collin, was overwhelmed at the time by various life pressures and mental health issues. Seeing this living saint arrive, he was deeply moved.

Consequently, trust was established. Slowly, the creator handed over the commit rights for the core codebase to him.

Even after getting the permissions, Jia Tan still wasn’t in a rush to commit the crime. Instead, he continued to diligently work for free. It wasn’t until early 2024 that, using extremely complex code obfuscation, he quietly slipped in a backdoor capable of controlling countless servers worldwide.

He almost got away with it.

Why was he ultimately exposed? Because a Microsoft engineer named Andres Freund, while conducting system performance tests, noticed that when logging into the server via SSH, the CPU spun just a tiny bit longer, causing the login to be 500 milliseconds slower.

Just 500 milliseconds.

If it weren’t for this god-tier engineer’s obsessive-compulsive nature, insisting on tearing apart the lowest of the low levels to see exactly which line of code was causing the slowdown, Jia Tan might have successfully installed his backdoor on servers across the globe. Tell me about it, the sheer drama of this incident is something not even Hollywood screenwriters would dare pen. A flawless sleeper agent who stayed hidden for two years, taken down by a programmer annoyed that his computer lagged for half a second.

This mysterious Jia Tan has become a legend in cybersecurity history
Who this Jia Tan really is remains a mystery to this day

4. Who Watches the Watchmen?

Whether it’s Chris buying trust with money or Jia Tan faking hardship to deceive people for trust, they both expose the most fragile side of the open-source world.

In the coding world, a change in ownership is often the catalyst for risk outbreaks. Subconsciously, people always assume that as long as it’s a familiar name and a tool they’ve always used, it will remain safe forever. Just like when you’re used to buying breakfast at the bun shop downstairs, you don’t check every day to see if the owner has changed.

But reality is quite cruel.

The creators behind many small open-source tools used by millions of people might just be college students running on passion, or working-class individuals painstakingly coding after their day jobs. When someone waves tens of thousands of dollars to buy their project, how many can really refuse? Furthermore, official stores lack any review mechanisms for “ownership transfers,” turning this into a massive trust blind spot.

Honestly, this is an almost unsolvable dilemma.

We can’t expect every developer to fuel their projects purely with love until they die, nor can we expect all mergers and acquisitions to come with state-level security audits. When trust becomes a legally transferable commodity—or even an investable asset—no matter how expensive your firewall is, it can’t stop legal code slipping in right through the front door. 🤷‍♀️

I’ve written quite a bit today. I originally wanted to throw in a few complaints about the WordPress official team’s sluggish response times, but never mind, we’ll save that for a separate chat next time. I need to hurry to my backend to check exactly how many broken plugins I have installed on my blog that haven’t been updated in centuries.

So, fellow webmasters, the next time you see those familiar plugin pop-ups prompting you with “A new version is available to update,” will you still dare to click upgrade with your eyes closed like you used to?


References:

—— Lyra Celest @ Turbulence τ.

Leave a Reply

Your email address will not be published. Required fields are marked *