Okendo Reviews Script Abused to Spread SmartApeSG Malware Campaign
Key Takeaways A supply chain attack targeted thousands of e-commerce websites by injecting malicious JavaScript into the Okendo Reviews widget. The SmartApeSG threat group, also known as ZPHP and...
Key Takeaways
- A supply chain attack targeted thousands of e-commerce websites by injecting malicious JavaScript into the Okendo Reviews widget.
- The SmartApeSG threat group, also known as ZPHP and HANEYMANEY, leveraged this compromise to deliver remote access tools (RATs) and information stealers like NetSupport RAT, Remcos RAT, StealC, and Sectop RAT.
- The attack employed a multi-stage loader, using environmental checks and social engineering (fake CAPTCHA/ClickFix) to trick users into executing malicious PowerShell or HTML Application files.
- Zscaler ThreatLabz detected the campaign on May 14, 2026, and Okendo swiftly remediated the compromised script, though many users may have been exposed.
SmartApeSG Leverages Okendo Reviews Widget for Widespread E-commerce Attack
A sophisticated supply chain attack has exposed numerous e-commerce platforms to malware by exploiting a widely adopted third-party review solution. Threat actors associated with the SmartApeSG campaign injected malicious JavaScript into the Okendo Reviews widget, a service utilized by over 18,000 global brands, to distribute malware to visitors of affected online stores.
Table Of Content
The attack remained covert, meaning customers browsing compromised e-commerce sites were unaware that a script on the page was profiling their systems and preparing to deploy harmful payloads. Okendo’s widget is commonly integrated into high-traffic areas such as homepages, product listings, and review submission forms, making it an attractive target for threat actors aiming to maximize their reach.
Zscaler ThreatLabz analysts first identified this activity on May 14, 2026, noting a significant increase in traffic linked to the SmartApeSG threat group. In a detailed report shared with Cyber Security News (CSN), Zscaler confirmed the presence of malicious code embedded within the legitimate widget script, characterizing it as a supply chain compromise with the potential to impact any website incorporating the Okendo widget.
SmartApeSG, also identified as ZPHP and HANEYMANEY, is a known entity in the cybersecurity landscape. This group has been implicated in previous campaigns distributing potent tools such as NetSupport RAT, Remcos RAT, StealC, and Sectop RAT. These programs grant attackers remote control over victim computers or facilitate the exfiltration of sensitive data, including login credentials and financial information.
Upon discovery, ThreatLabz promptly informed Okendo, who confirmed awareness of the issue. Okendo responded swiftly, restoring the affected widget script to a secure state and neutralizing the active threat. However, the period during which the malicious script was active could have exposed a substantial number of visitors across a broad spectrum of websites.
How the Okendo Reviews Script Was Abused
The attackers strategically targeted a popular third-party widget, enabling them to achieve extensive reach without individually compromising each e-commerce site. The malicious JavaScript functioned as a multi-stage loader, executing its actions incrementally. It performed environmental checks before fetching subsequent malicious content.
The script employed browser-based tracking via localStorage to prevent repeated execution on the same device. It also analyzed the visitor’s User-Agent string to filter for desktop users, as later stages of the attack relied on Windows-specific interactions. After these initial checks, the script utilized an XOR-based decoding mechanism to reconstruct a hidden URL, which was then loaded as a new script element to retrieve the next stage of the attack.

Victims who passed these filters were presented with a fraudulent CAPTCHA or verification screen, a tactic known as ClickFix. These prompts instructed users to open the Windows Run menu and paste a command that had been silently copied to their clipboard.

This command subsequently downloaded a PowerShell script or an HTML Application file, leading to the installation of a remote access tool or an information stealer on the victim’s computer.
Estimated Reach and Scale of the Campaign
The scope of this incident is considerable. ThreatLabz observed the compromised widget on websites ranging from medium-sized online stores to major retail brands. Traffic estimates for the affected sites varied from approximately 150,000 to several million monthly visitors, with one U.S. retail brand alone reportedly attracting around 7 million visitors each month.

On May 14, 2026, Zscaler’s platform recorded nearly 15,000 blocks related to SmartApeSG in a single day, illustrating the intense activity of the campaign at its peak. While these figures represent blocked attempts rather than confirmed infections, they underscore the rapid propagation potential of a supply chain compromise when a widely used vendor is targeted.
Website administrators relying on third-party scripts should regularly audit their integrations and monitor for any anomalous behavior on their web pages.
What You Should Do
- E-commerce Website Owners: Regularly audit all third-party scripts and integrations on your site, including review widgets, analytics, and advertising scripts. Implement Content Security Policy (CSP) headers to restrict script execution to trusted sources.
- Users of E-commerce Sites: Exercise caution when prompted to perform unusual actions, such as opening the Run menu and pasting commands, even on seemingly legitimate websites. Keep your operating system and web browser updated.
- Security Teams: Monitor network traffic for connections to known SmartApeSG indicators of compromise (IoCs). Implement robust endpoint detection and response (EDR) solutions to identify and block suspicious script execution and malware downloads.
- All Organizations: Educate employees and users about social engineering tactics like fake CAPTCHAs and the dangers of executing untrusted commands.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxp://cdn-static[.]okendo[.]io/reviews-widget-plus/js/okendo-reviews[.]js | Compromised Okendo Reviews widget script URL |
| URL | hxxps://api[.]wigetticks[.]com/logout/private-response[.]php?8D1V4th3 | SmartApeSG next-stage delivery URL |
| URL | hxxps://api[.]wizzleticks[.]com/claims/scope-schema[.]php?4ManBBdA | SmartApeSG next-stage delivery URL |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.