Skip to content
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack

SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack

First seen 19 Jun 2026, 13:08 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 20, 2026 at 12:52 UTC
  • SmartApeSG injected malicious JavaScript into the Okendo Reviews widget used by over 18,000 brands.
  • The attack utilized advanced obfuscation techniques to conceal malicious activities and limit detection.
  • Okendo confirmed the incident and restored the compromised widget to a secure state.

On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of staged malware across numerous e-commerce websites, impacting high-visibility pages such as homepages and product information pages. The injected code utilized obfuscation techniques to conceal its activities and limit detection, employing localStorage for state tracking to suppress repeated executions. Zscaler confirmed the incident and reported it to Okendo, which restored the widget to a clean state. The attack exemplifies the risks associated with third-party widget dependencies in web applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-05-14
SmartApeSG launched supply chain attack
Malicious JavaScript was injected into the Okendo Reviews widget, affecting numerous e-commerce sites.
Zscaler
2026-06-18
Blumira reports obfuscation techniques used by SmartApeSG
Blumira detailed advanced obfuscation methods employed by SmartApeSG in their malware delivery.
Blumira
2026-06-19
Gbhackers report on SmartApeSG's attack
Gbhackers confirmed the supply chain compromise of the Okendo Reviews widget, detailing its impact.
Gbhackers
2026-06-19
Cybersecuritynews covers SmartApeSG attack
Cybersecuritynews reported on the risks posed by the SmartApeSG campaign targeting the Okendo widget.
Cybersecuritynews

More articles in this cluster (4)

Following this threat?

Track SmartApeSG, ClearFake and Okendo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed