Zscaler
SmartApeSG Targets Okendo Reviews Widget in Supply Chain Attack
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On May 14, 2026, the SmartApeSG threat actor launched a supply chain attack by injecting malicious JavaScript into the Okendo Reviews widget, which is used by over 18,000 brands. This compromise allowed the delivery of staged malware across numerous e-commerce websites, impacting high-visibility pages such as homepages and product information pages. The injected code utilized obfuscation techniques to conceal its activities and limit detection, employing localStorage for state tracking to suppress repeated executions. Zscaler confirmed the incident and reported it to Okendo, which restored the widget to a clean state. The attack exemplifies the risks associated with third-party widget dependencies in web applications.
Key Points: • SmartApeSG injected malicious JavaScript into the Okendo Reviews widget used by over 18,000 brands. • The attack utilized advanced obfuscation techniques to conceal malicious activities and limit detection. • Okendo confirmed the incident and restored the compromised widget to a secure state.