SmartApeSG Launches Okendo Reviews Supply Chain Attack

From the source: Zscaler ThreatLabz

On May 14, 2026, the Zscaler ThreatLabz team identified unusually high activity associated with the threat actor SmartApeSG to deploy malware. During our examination, we discovered malicious JavaScript code embedded in a legitimate reviews widget found on numerous websites. Our analysis revealed that the affected component was the Okendo Reviews widget, a popular customer review…

Read the full story on Zscaler ThreatLabz
Originally published by Zscaler ThreatLabz on 19 June 2026. Techarda links to the original rather than republishing it. Read the full article →

Have you worked with this?

The story is what was announced. Nobody has discussed it yet, so if it touches your team, a short post about what you’ve seen helps the next reader.

Start the discussion

More from Zscaler

Recent updates from Zscaler, so you can tell whether this is a one-off or part of a pattern.

All Zscaler news →
SecurityWhy it matters

Threat Actors Use Google Ads To Target Ledger Users

In August 2026, Zscaler ThreatLabz analyzed a phishing campaign that used fraudulent Google ads to target Ledger hardware wallet users. The ads redirected users through Google Cloud Storage and Vercel to a Google Sites page containing a phishing page impersonating Ledger in an iframe. During our analysis, the Vercel redirect appeared to change every 15-20 minutes. There, a fake…

Zscaler·via Zscaler ThreatLabz
Security

Vidar Adds Virtual Machine and Custom Stream Ciphers For String Obfuscation

Vidar is an information stealer that was first observed in 2018. Across its iterations, Vidar has continued to improve its string obfuscation to make detection and analysis more difficult by changing deobfuscation algorithms, constants, and primitives. From May through early September 2026, Zscaler ThreatLabz tracked Vidar’s string obfuscation as it evolved from basic XOR to ChaCha20,…

Zscaler·via Zscaler ThreatLabz
Security

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense…

Zscaler·via Zscaler ThreatLabz

More in Security

What other companies in Security are doing. The category page shows who’s active, side by side.

Compare companies in Security →
SecurityNew

The Developer is the New Perimeter: How Supply Chain Attacks Are Becoming Cloud Breaches

A routine package install can open the door to a cloud breach. Learn how attackers exploit developer credentials. Discover practical steps to contain exposure and protect your cloud environment.

Qualys·via Qualys Blog
SecurityNew

Next.js applications, powered by Vite: introducing Vinext 1.0

Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline.

Cloudflare·via Cloudflare Blog
SecurityNew

Introducing cf: the agentic CLI for the entire Cloudflare API

We are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator.

Cloudflare·via Cloudflare Blog
SecurityNew

How fast is the web? Explore billions of real-user measurements with BEACON

Cloudflare is open-sourcing the BEACON dataset, making billions of anonymized Real User Monitoring (RUM) performance records publicly available on Google BigQuery. Explore real-world Core Web Vitals, soft navigation metrics, and performance breakdowns across browsers and regions.

Cloudflare·via Cloudflare Blog