Austin Ginder, a WordPress hosting operator managing thousands of sites, describes how he accidentally uncovered a pattern of supply chain attacks targeting WordPress plugins. Bad actors are either purchasing legitimate plugins or hijacking their update mechanisms to redirect updates from wordpress.org to rogue servers, silently distributing malware to end users. Ginder details four specific cases including the Essential Plugins package and Widget Logic plugin, and explains how AI tools like Claude Code made forensic investigation feasible for individuals. He created WP Beacon (wpbeacon.io) as a tracking resource for supply chain attacks specifically, distinct from traditional vulnerability databases. He advocates for AI-powered code auditing of all plugin updates and greater collaboration between security researchers and hosting providers to detect and dismantle attacker infrastructure.