This is a supply chain attack hitting the ecommerce space. BigCommerce is notifying merchants that attackers compromised credentials for third-party Ribon apps and used that access to inject malicious scripts into online stores.
Technical Breakdown – Attack Vector: Credential compromise of third-party Ribon applications, not a direct breach of BigCommerce core infrastructure. – Impact: Malicious script injection into merchant storefronts, likely targeting payment data or customer PII via form grabbing. – Scope: Multiple merchants affected; specific number not disclosed. – Attribution: No named threat actor at this time.
Defense – If you're a BigCommerce merchant using Ribon apps, immediately rotate API keys and app credentials. – Audit your storefront for unauthorized script injections—check for unexpected JavaScript loaded from external domains. – Enable Content Security Policy (CSP) headers to restrict script sources and limit blast radius from compromised third-party apps. – Review third-party app permissions and remove any that are unused or have excessive access.
Source: r/SecOpsDaily · by /u/falconupkid