CRITICAL: Smart Slider 3 Pro 3.5.1.35 is a COMPROMISED build - treat this site as HACKED
The Smart Slider 3 Pro 3.5.1.35 release for Joomla is a malicious build pushed through a breach of the Nextend update infrastructure. Any Joomla site that installed this version must be treated as fully compromised: the payload creates hidden Super User accounts (typically usernames beginning wpsvc_), drops backdoor files at /cache/cf_check.php and /media/cf_check.php, allows remote code execution and exfiltrates credentials. Update to Smart Slider 3 Pro 3.5.1.36 immediately, manually remove any wpsvc_ Super Users, delete the cf_check.php backdoor files, reinstall Joomla core and every extension from clean sources, and rotate every credential (Joomla admins, FTP, database, hosting and email). Also within this rule: CVE-2026-34424 (NVD record for this same compromised 3.5.1.35 build).
Affected versions: exactly 3.5.1.35
Full advisory: our disclosure post