"Two supply chain attacks in two weeks. Both followed the same pattern.
Buy a trusted plugin with an established install base, inherit the #WordPress.org commit access, and inject malicious code. [...]
WordPress.org has no mechanism to flag or review plugin ownership transfers."
I wonder if the Drupal marketplace folks have considered ownership transfer issues...
https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/





