Hackers Compromised ILSpy WordPress Domain to Deliver Malware
A new supply chain attack targeting developers after threat actors compromised the official WordPress domain for ILSpy on April 6, 2026. Instead of providing the legitimate software, the hijacked website began redirecting visitors to a malicious webpage to deliver malware. Normally, clicking the download button on the ILSpy website sends users directly to the project’s […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
