Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
https://wpscan.com/vulnerability/7ca5ad30-1792-4014-bfad-88911cd64713/