Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
vendor-distribution-compromiseloader-delivery-mechanismremote-access-implantcommand-and-control-method

SmartApeSG Injects Malicious Code Into Okendo Reviews Widget

Updated 1d agoFirst seen Jun 18, 20263 sources

Threat researchers reported that the SmartApeSG threat actor, also tracked as ZPHP and HANEYMANEY, compromised the legitimate Okendo Reviews widget in a supply chain attack that exposed downstream websites, particularly high-traffic e-commerce pages. The malicious JavaScript acted as a staged loader rather than an immediate payload, using localStorage to limit repeat execution, User-Agent filtering to prioritize desktop victims and exclude mobile devices, and XOR-obfuscated string fragments to rebuild command-and-control infrastructure at runtime before dynamically loading additional scripts.

Researchers said the activity is consistent with earlier SmartApeSG campaigns that used ClickFix-style fake CAPTCHA lures to trick users into launching follow-on malware through Windows Run, PowerShell, or HTA downloaders. Those campaigns have delivered payloads including NetSupport RAT, Remcos RAT, StealC, and Sectop RAT. Okendo said it was aware of the incident and restored the widget to a clean state, while telemetry showed a sharp spike in detections on May 14, with nearly 15,000 blocks in a single day, suggesting broad exposure across affected sites.

Share:
SmartApeSG Injects Malicious Code Into Okendo Reviews Widget
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 18, 20262d ago

Okendo restores compromised widget script to a clean state

Okendo confirmed it was aware of the incident and said the affected widget script had been restored to a clean state following the compromise.

SmartApeSG Launches Okendo Reviews Supply Chain Attack - Malware News - Malware Analysis, News and Indicators

ThreatLabz publishes SmartApeSG Okendo supply chain attack analysis

Zscaler ThreatLabz published research attributing the staged JavaScript loader in the compromised Okendo Reviews script to SmartApeSG, also tracked as ZPHP or HANEYMANEY. The report detailed execution control, environment filtering, deobfuscation, and dynamic retrieval of follow-on payloads used in the campaign.

SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz
May 14, 20261mo ago

ThreatLabz detects malicious Okendo Reviews widget activity

Zscaler ThreatLabz discovered a supply chain attack involving malicious JavaScript injected into the legitimate Okendo Reviews widget. ThreatLabz also observed a sharp spike in detections that day, with nearly 15,000 blocks, indicating potentially broad exposure across downstream sites.

SmartApeSG Launches Okendo Reviews Supply Chain Attack - Malware News - Malware Analysis, News and Indicators
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Windows
Organizations
3 linked
ZscalerOkendoCyber Security News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

SmartApeSG Injects Malicious Code Into Okendo Reviews Widget | Mallory