Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft June 2026 Bug Exposes Recycle Update Filenames
June 19, 2026
HazyBeacon Weaponizes AWS Lambda URLs for Stealth C2
June 19, 2026
Hackers Exploit Okendo Reviews Script to Spread Smart
June 19, 2026
Home/Threats/Hackers Exploit Okendo Reviews Script to Spread Smart
Threats

Hackers Exploit Okendo Reviews Script to Spread Smart

A new supply chain attack has exposed thousands of e-commerce websites to risk, leveraging a popular third-party reviews widget as a stealthy malware delivery mechanism. This campaign, detailed in a...

Emy Elsamnoudy
Emy Elsamnoudy
June 19, 2026 4 Min Read
3 0

A new supply chain attack has exposed thousands of e-commerce websites to risk, leveraging a popular third-party reviews widget as a stealthy malware delivery mechanism. This campaign, detailed in a Threat actors behind the SmartApeSG campaign injected malicious JavaScript into the Okendo Reviews widget, a platform trusted by more than 18,000 brands worldwide, to push malware to unsuspecting visitors.

The attack unfolded silently, meaning visitors to affected online stores had no idea that a script running on the page was scanning their system and preparing to serve malicious content.

The Okendo widget is typically embedded on high-traffic pages, including store homepages, product pages, and review submission forms, making it an ideal point of compromise for attackers looking to reach a wide audience.

Analysts from Zscaler ThreatLabz first spotted this activity on May 14, 2026, when they noticed an unusual surge in traffic linked to the SmartApeSG threat actor. 

Zscaler said in a report shared with Cyber Security News (CSN) that their team discovered malicious code hidden inside the legitimate widget script, and that the attack represented a clear supply chain compromise capable of affecting any site using the widget.

SmartApeSG, also tracked under the names ZPHP and HANEYMANEY, is not a new name in the threat landscape.

The group has been linked to past campaigns that delivered dangerous tools including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.

These are programs that allow attackers to take control of a victim’s computer remotely or steal sensitive data like passwords and financial credentials.

Following the discovery, ThreatLabz reported the incident to Okendo directly, and the company confirmed it was aware of the issue. Okendo acted quickly and restored the widget script to a clean state, stopping the active threat.

However, the window during which the malicious script was live may have been long enough to expose a significant number of visitors across many websites.

Hackers Abuse Third-Party Okendo Reviews Script

The attackers chose their target wisely. By compromising a widely used third-party widget rather than individual websites, they extended their reach dramatically without needing to breach each site separately.

The malicious JavaScript acted as a staged loader, meaning it did not execute all of its actions at once. Instead, it moved step by step, checking the environment before pulling in additional content.

The script used browser-based tracking through localStorage to prevent repeated execution on the same device. It also checked the visitor’s

User-Agent string to filter out mobile users and focus on desktops, since later stages of the attack relied on Windows-based interactions.

Once those checks passed, the script used an XOR-based decoding routine to quietly rebuild a hidden URL, which it then loaded as a new script element to fetch the next stage.

Malicious SmartApeSG JavaScript code injected into the Okendo Reviews script (Source - Zscaler)
Malicious SmartApeSG JavaScript code injected into the Okendo Reviews script (Source – Zscaler)

Victims who passed these filters were shown a fake CAPTCHA or verification screen, a technique known as ClickFix.

These prompts instructed users to open the Windows Run menu and paste a command that was already copied silently to their clipboard.

SmartApeSG loader workflow overview (Source - Zscaler)
SmartApeSG loader workflow overview (Source – Zscaler)

That command then pulled down a PowerShell script or HTML Application file, which installed a remote access tool or information stealer on the victim’s machine.

Estimated Reach and Scale of the Campaign

The scale of this attack is hard to ignore. ThreatLabz observed the compromised widget running on websites ranging from mid-sized online shops to large retail brands.

Traffic estimates for affected sites ranged from around 150,000 to several million monthly visitors, and one impacted U.S. retail brand alone draws approximately 7 million visitors per month.

SmartApeSG blocks on a log scale in the Zscaler cloud in May 2026 (Source - Zscaler)
SmartApeSG blocks on a log scale in the Zscaler cloud in May 2026 (Source – Zscaler)

On May 14, 2026 alone, Zscaler’s platform recorded nearly 15,000 blocks tied to SmartApeSG in a single day, reflecting how intense the campaign was at its peak.

While these numbers represent blocked attempts and not confirmed infections, they highlight how fast a supply chain compromise can spread when a popular vendor is targeted.

Website owners who rely on third-party scripts should audit their integrations and watch closely for any unexpected behavior on their pages.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxp://cdn-static[.]okendo[.]io/reviews-widget-plus/js/okendo-reviews[.]js Compromised Okendo Reviews widget script URL
URL hxxps://api[.]wigetticks[.]com/logout/private-response[.]php?8D1V4th3 SmartApeSG next-stage delivery URL
URL hxxps://api[.]wizzleticks[.]com/claims/scope-schema[.]php?4ManBBdA SmartApeSG next-stage delivery URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

INC Ransomware Attacks Use Rust Encryptors Uses Rust-Based

Next Post

HazyBeacon Weaponizes AWS Lambda URLs for Stealth C2

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
China-Linked Showboat Malware Targets Telecom via Linux
June 19, 2026
Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity
June 19, 2026
CISA Warns: Splunk Enterprise Critical Fl Function Vulnerability
June 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us