Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Trezor ShipMonk Data Breach Exposes 13,000+ Hardware Wallet Customers’ Personal Data
August 13, 2026
Critical Microsoft Exchange Server Bugs Allow RCE and DoS Attacks
August 13, 2026
North Korean IT Workers Impersonate Employees Using Forged IDs
August 13, 2026
Home/Threats/Okendo Reviews Script Abused to Spread SmartApeSG Malware Campaign
Threats

Okendo Reviews Script Abused to Spread SmartApeSG Malware Campaign

Key Takeaways A supply chain attack targeted thousands of e-commerce websites by injecting malicious JavaScript into the Okendo Reviews widget. The SmartApeSG threat group, also known as ZPHP and...

Emy Elsamnoudy
Emy Elsamnoudy
June 19, 2026 4 Min Read
51 0

Key Takeaways

  • A supply chain attack targeted thousands of e-commerce websites by injecting malicious JavaScript into the Okendo Reviews widget.
  • The SmartApeSG threat group, also known as ZPHP and HANEYMANEY, leveraged this compromise to deliver remote access tools (RATs) and information stealers like NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
  • The attack employed a multi-stage loader, using environmental checks and social engineering (fake CAPTCHA/ClickFix) to trick users into executing malicious PowerShell or HTML Application files.
  • Zscaler ThreatLabz detected the campaign on May 14, 2026, and Okendo swiftly remediated the compromised script, though many users may have been exposed.

SmartApeSG Leverages Okendo Reviews Widget for Widespread E-commerce Attack

A sophisticated supply chain attack has exposed numerous e-commerce platforms to malware by exploiting a widely adopted third-party review solution. Threat actors associated with the SmartApeSG campaign injected malicious JavaScript into the Okendo Reviews widget, a service utilized by over 18,000 global brands, to distribute malware to visitors of affected online stores.

Table Of Content

  • Key Takeaways
  • SmartApeSG Leverages Okendo Reviews Widget for Widespread E-commerce Attack
  • How the Okendo Reviews Script Was Abused
  • Estimated Reach and Scale of the Campaign
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The attack remained covert, meaning customers browsing compromised e-commerce sites were unaware that a script on the page was profiling their systems and preparing to deploy harmful payloads. Okendo’s widget is commonly integrated into high-traffic areas such as homepages, product listings, and review submission forms, making it an attractive target for threat actors aiming to maximize their reach.

Zscaler ThreatLabz analysts first identified this activity on May 14, 2026, noting a significant increase in traffic linked to the SmartApeSG threat group. In a detailed report shared with Cyber Security News (CSN), Zscaler confirmed the presence of malicious code embedded within the legitimate widget script, characterizing it as a supply chain compromise with the potential to impact any website incorporating the Okendo widget.

SmartApeSG, also identified as ZPHP and HANEYMANEY, is a known entity in the cybersecurity landscape. This group has been implicated in previous campaigns distributing potent tools such as NetSupport RAT, Remcos RAT, StealC, and Sectop RAT. These programs grant attackers remote control over victim computers or facilitate the exfiltration of sensitive data, including login credentials and financial information.

Upon discovery, ThreatLabz promptly informed Okendo, who confirmed awareness of the issue. Okendo responded swiftly, restoring the affected widget script to a secure state and neutralizing the active threat. However, the period during which the malicious script was active could have exposed a substantial number of visitors across a broad spectrum of websites.

How the Okendo Reviews Script Was Abused

The attackers strategically targeted a popular third-party widget, enabling them to achieve extensive reach without individually compromising each e-commerce site. The malicious JavaScript functioned as a multi-stage loader, executing its actions incrementally. It performed environmental checks before fetching subsequent malicious content.

The script employed browser-based tracking via localStorage to prevent repeated execution on the same device. It also analyzed the visitor’s User-Agent string to filter for desktop users, as later stages of the attack relied on Windows-specific interactions. After these initial checks, the script utilized an XOR-based decoding mechanism to reconstruct a hidden URL, which was then loaded as a new script element to retrieve the next stage of the attack.

Malicious SmartApeSG JavaScript code injected into the Okendo Reviews script (Source - Zscaler)
Malicious SmartApeSG JavaScript code injected into the Okendo Reviews script (Source – Zscaler)

Victims who passed these filters were presented with a fraudulent CAPTCHA or verification screen, a tactic known as ClickFix. These prompts instructed users to open the Windows Run menu and paste a command that had been silently copied to their clipboard.

SmartApeSG loader workflow overview (Source - Zscaler)
SmartApeSG loader workflow overview (Source – Zscaler)

This command subsequently downloaded a PowerShell script or an HTML Application file, leading to the installation of a remote access tool or an information stealer on the victim’s computer.

Estimated Reach and Scale of the Campaign

The scope of this incident is considerable. ThreatLabz observed the compromised widget on websites ranging from medium-sized online stores to major retail brands. Traffic estimates for the affected sites varied from approximately 150,000 to several million monthly visitors, with one U.S. retail brand alone reportedly attracting around 7 million visitors each month.

SmartApeSG blocks on a log scale in the Zscaler cloud in May 2026 (Source - Zscaler)
SmartApeSG blocks on a log scale in the Zscaler cloud in May 2026 (Source – Zscaler)

On May 14, 2026, Zscaler’s platform recorded nearly 15,000 blocks related to SmartApeSG in a single day, illustrating the intense activity of the campaign at its peak. While these figures represent blocked attempts rather than confirmed infections, they underscore the rapid propagation potential of a supply chain compromise when a widely used vendor is targeted.

Website administrators relying on third-party scripts should regularly audit their integrations and monitor for any anomalous behavior on their web pages.

What You Should Do

  • E-commerce Website Owners: Regularly audit all third-party scripts and integrations on your site, including review widgets, analytics, and advertising scripts. Implement Content Security Policy (CSP) headers to restrict script execution to trusted sources.
  • Users of E-commerce Sites: Exercise caution when prompted to perform unusual actions, such as opening the Run menu and pasting commands, even on seemingly legitimate websites. Keep your operating system and web browser updated.
  • Security Teams: Monitor network traffic for connections to known SmartApeSG indicators of compromise (IoCs). Implement robust endpoint detection and response (EDR) solutions to identify and block suspicious script execution and malware downloads.
  • All Organizations: Educate employees and users about social engineering tactics like fake CAPTCHAs and the dangers of executing untrusted commands.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxp://cdn-static[.]okendo[.]io/reviews-widget-plus/js/okendo-reviews[.]js Compromised Okendo Reviews widget script URL
URL hxxps://api[.]wigetticks[.]com/logout/private-response[.]php?8D1V4th3 SmartApeSG next-stage delivery URL
URL hxxps://api[.]wizzleticks[.]com/claims/scope-schema[.]php?4ManBBdA SmartApeSG next-stage delivery URL

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachExploitHackerMalwareSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

INC Ransomware Leverages Rust Encryptors for Windows, Linux, and ESXi Attacks

Next Post

HazyBeacon Abuses AWS Lambda URLs for Stealthy C2 Relays

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Jewelbug APT Hijacks Browsers to Steal Cookies, Spy on Government Networks
August 13, 2026
GitLab 16.2.2 Patches High-Severity XSS and CI/CD Authorization Flaws
August 13, 2026
Critical Vulnerability in Schneider Electric APC NetBotz Exposes Data Centers
August 13, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us