# Smart Slider 3 Pro 3.5.1.35 Backdoor via Supply Chain Attack

> Nextend's Smart Slider 3 Pro version 3.5.1.35 was compromised via a supply chain attack. Learn how to identify and remediate the backdoor today.

- Published: 2026-04-10T08:37:51.000Z
- Severity: high
- Category: Supply Chain
- Tags: Smart Slider 3 Pro, WordPress Security, Nextend, Backdoor, Supply Chain Attack
- Author: Runtime Rebel Intel
- Primary source: https://thehackernews.com/2026/04/backdoored-smart-slider-3-pro-update.html
- Canonical: https://runtimerebel.com/blog/smart-slider-3-pro-3-5-1-35-backdoor-via-supply-chain-attack

## Key points

- Immediate impact: Attackers can gain persistent access and execute arbitrary code on websites running the compromised slider plugin update.
- Affected systems: Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla distributed via hijacked Nextend update servers.
- Remediation: Administrators must verify the integrity of plugin files and update immediately to the clean version 3.5.1.36.

Nextend, the developer behind the widely used Smart Slider 3 plugin, has reported a significant security incident involving the hijacking of their software distribution infrastructure. According to [The Hacker News](https://thehackernews.com/2026/04/backdoored-smart-slider-3-pro-update.html), unknown threat actors successfully compromised the company's update servers to distribute a malicious version of the Smart Slider 3 Pro plugin. This [Supply Chain Attack](/glossary#supply-chain-attack) specifically targets version 3.5.1.35 of the Pro edition, embedding a backdoor designed to grant attackers persistent access to the underlying web server.

The technical implications of a compromised plugin update are severe. Once the backdoored update is installed, the malicious code typically establishes a [C2](/glossary#c2) channel, enabling the adversary to perform unauthorized [RCE](/glossary#rce) tasks. Because the plugin operates within the context of the content management system (CMS) with permissions to modify site files, this compromise can lead to full site takeover, data exfiltration, or the deployment of [Ransomware](/glossary#ransomware). Security researchers at Patchstack, who monitored the incident, noted that while the free version of Smart Slider 3 remains unaffected, the Pro version's automated update mechanism was leveraged to bypass standard security filters. Smart Slider 3 is a popular WordPress slider plugin with more than 800,000 active installations, making the potential reach of this campaign substantial.

### Analyzing the Attack Vector
The hijacking of Nextend's update servers represents a sophisticated breach of the software distribution pipeline. By compromising the source of the updates, the attackers ensured that the malicious payload was distributed through trusted channels, which often circumvents traditional [EDR](/glossary#edr) solutions that focus on signature-based detection for known malware. Security teams should analyze their [SIEM](/glossary#siem) logs for unusual outbound traffic originating from web servers, which may indicate the backdoor attempting to beacon to an external controller.

Defenders must understand **how to detect Smart Slider 3 Pro backdoor** activity within their environments. This involves more than just a simple file hash check; administrators should look for unauthorized modifications in the plugin’s directory, specifically focusing on PHP files that have been modified outside of the standard update window or that contain obfuscated code snippets. Any [IoC](/glossary#ioc) related to this incident should be immediately ingested into the [SOC](/glossary#soc) workflow for broader threat hunting across the enterprise.

## Smart Slider 3 Pro 3.5.1.35 Patch Guidance and Remediation
The primary remediation step is the immediate removal of the compromised version and an upgrade to a verified clean version. Nextend has regained control of their infrastructure and released version 3.5.1.36 to address the compromise. Organizations should follow this **Smart Slider 3 Pro 3.5.1.35 patch guidance** to ensure the integrity of their web assets:

*   Audit all WordPress and Joomla installations to identify the specific version of the Smart Slider 3 Pro plugin currently in use.
*   If version 3.5.1.35 is detected, assume the environment is potentially compromised and initiate an incident response plan to check for persistence.
*   Replace the plugin files with a fresh download of version 3.5.1.36 or higher directly from the official Nextend portal rather than relying on cached versions.
*   Rotate all credentials associated with the website, including database passwords, FTP accounts, and administrative user credentials, as these may have been harvested by the backdoor prior to detection.

While no specific [CVE](/glossary#cve) identifier has been assigned to this server-side compromise at the time of reporting, the severity of the incident aligns with high-impact vulnerabilities described in the [MITRE ATT&CK](/glossary#mitre-att-ck) framework under Supply Chain Compromise. Maintaining a [Zero Trust](/glossary#zero-trust) approach to third-party integrations remains the most effective long-term defense against similar infrastructure-level breaches.

**Related:** [Fake Next.js Job Interview Tests Backdoor Developers](/blog/fake-next-js-job-interview-tests-backdoor-developers), [CVE-2023-3800: RCE Vulnerability in Ninja Forms File Uploads Extension](/blog/cve-2023-3800-rce-vulnerability-in-ninja-forms-file-uploads-extension)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/smart-slider-3-pro-3-5-1-35-backdoor-via-supply-chain-attack
