Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. A JavaScript file named "w2.js," the payload performs the following actions -Contacts the C2 server ("ia-cdn[. The execution is aborted if the C2 server returns a "skip" or "done" status. The generated credentials are then leveraged to create a malicious administrator user, and the results of the attack are then exfiltrated back to the C2 server. The C2 server used in the campaign is assessed to be related to two other software supply chain attacks involving Advanced Responsive Video Embedder (CVE-2026-18072) and OptinMonster in recent months.