Skip to content
ILSpy WordPress Domain Breached to Distribute Malware

ILSpy WordPress Domain Breached to Distribute Malware

First seen 6 Apr 2026, 11:43 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 7, 2026 at 10:32 UTC
  • •ILSpy's official WordPress domain was compromised to deliver malware.
  • •The attack targets developers relying on ILSpy for .NET code analysis.
  • •Users are advised to avoid the compromised site until it is secured.

On April 6, 2026, hackers compromised the official WordPress domain for ILSpy, a widely used open-source tool for .NET code analysis. The breach redirected users from the legitimate site to a malicious webpage designed to deliver malware. This supply chain attack specifically targets software developers who rely on ILSpy for their projects. The incident was confirmed by the Redirection Attack Cybersecurity research group vx-underground, which provided evidence of the breach. Users attempting to download ILSpy software were instead exposed to potential malware infections. The scope of the attack affects all visitors to the compromised site. As of now, the situation is ongoing, and users are advised to avoid the site until further notice.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 187d ago How this analysis works

Timeline

2026-04-06
ILSpy WordPress domain compromised to deliver malware.
2026-04-06
vx-underground confirms the breach with evidence.

More articles in this cluster (3)

Following this threat?

Track ILSpy in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed