{
  "id": 9148537,
  "title": "BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials",
  "url": "https://urgent.news/2026/09/22/bigcommerce-third-party-app-compromise-malicious-script-injected-into",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-22T14:01:05.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/bigcommerce-third-party-app-compromise-malicious-script-injected-into-storefronts-via-ribon-53ma"
  },
  "original_language": "en",
  "account": "In September 2026, BigCommerce alerted merchants to a potential data breach involving third-party application credentials. The compromised credentials, belonging to the Ribon app and its Ribon 1.5 version, were used to access customer records and inject malicious scripts into some storefronts. BigCommerce stated that passwords and payment-card data remained secure, but the injected scripts have not been confirmed to execute in shoppers' browsers. The affected records contained personal details such as names, email addresses, phone numbers, and shipping addresses. BigCommerce provided logs to affected merchants to monitor for phishing attempts using exposed contact information. The threat actor sought to exploit the trust relationship between third-party apps and the BigCommerce platform, using the compromised application key to access and alter merchant data. To mitigate the risk, users should revoke the Ribon app, rotate credentials, and apply strict access controls.",
  "summary": "+09:00 Source : BleepingComputer Severity: High Basis for Severity: Compromised third-party application credentials were used to access existing customer records and inject malicious scripts into a small number of storefronts.…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}