BigCommerce warns merchants after third‑party Ribon app breach injects malicious code into stores
BigCommerce, a SaaS ecommerce platform serving thousands of online retailers, issued an urgent advisory on Monday informing merchants that a security incident involving the third‑party app provider Ribon has resulted in malicious scripts being placed on some storefronts.
According to the notice, threat actors obtained valid login credentials for several Ribon applications that integrate with BigCommerce stores. Using those credentials, the attackers were able to embed hidden JavaScript snippets into the HTML of affected merchant sites, a technique commonly used to harvest visitor data or redirect traffic to fraudulent pages.
The breach highlights the interdependence of platform and app ecosystems. BigCommerce allows merchants to install extensions from approved partners such as Ribon to add features like loyalty programs or checkout enhancements. Because these extensions run within the merchant’s domain, compromised credentials give attackers a direct line to modify the storefront’s front‑end code without triggering the platform’s own security controls.
While the advisory did not disclose the number of merchants impacted, the presence of malicious scripts could expose customer information, payment details, or lead to phishing attacks. The scripts are designed to execute in visitors’ browsers, potentially stealing cookies or redirecting users to sites that mimic legitimate checkout pages.
In response, BigCommerce has sent individualized alerts to all merchants known to use Ribon apps, urging them to revoke and regenerate API keys, review recent code changes, and monitor traffic for unusual patterns. The company also disabled the compromised Ribon integration points while it works with the app developer to secure the affected accounts.
Security experts say the incident underscores the need for continuous vetting of third‑party software and for merchants to adopt layered defenses such as content security policies and regular integrity checks. Both BigCommerce and Ribon have pledged to conduct a joint forensic investigation and to publish further findings, while industry regulators are watching to see if additional guidance on supply‑chain risks will be issued.
Comments (0)
Be the first to comment.
Join the discussion