Updates on Security Incident
Latest information about the recent security incident affecting Qikify Sticky Add to Cart & Qikify Mega Menu, Navigation.
Summary
On 22 July, 2026, we identified a security incident affecting two of our apps, Qikify Sticky Add to Cart and Qikify Mega Menu & Navigation. Based on our current investigation, a group of stores was affected.
We immediately addressed the issue, and the fix was completed within around 6.5 hours, from 11:10 PM (22 July, 2026) to 5:40 AM (23 July, 2026) (GMT+7).
We are still conducting a full investigation into all affected stores to check for any further issues.
This page provides the latest information about what happened, how we responded, and what you should do next. We will keep this page updated as we learn more.
What happened
What happened with Qikify Sticky Add to Cart:
Our app includes a setting that allows merchants to use custom HTML to provide greater flexibility when customizing the cart experience. Unfortunately, we identified a security vulnerability related to this feature that allowed unauthorized third parties to inject malicious scripts into the app settings.
In some affected stores, this could cause customers who clicked the Checkout button from the cart drawer to be redirected to an external page.
What happened with Qikify Mega Menu & Navigation:
This app has a similar custom HTML setting for the menu and navigation experience, which was affected by the same type of vulnerability.
In some affected stores, this could cause customers who clicked the Add to cart button to be redirected to an external advertising page.
--------
All of our other apps were NOT affected by this incident.
How we responded
Our Support and Engineering teams immediately began investigating and resolving the issue to minimize any potential impact.
After a thorough investigation, we successfully identified the root cause and fully resolved it within the system. We also performed a comprehensive review across affected stores and have removed all malicious scripts that were identified.
Based on our investigation to date, we found NO evidence that any merchant, store, customer, or shopper data was accessed, exposed, or leaked through the Qikify system as a result of this incident.
The incident was strictly limited to two customizable HTML content fields within the apps settings:
- For Qikify Sticky Add to Cart: Empty cart text, Sticky cart message.
- For Qikify Mega Menu, Navigation: Item title.
No other app settings, merchant configuration, Shopify store data, customer information, order data, payment information, or Shopify account credentials were affected or compromised.
Current status
We have shared our initial investigation findings with Shopify, and Shopify has confirmed receipt as part of their review process for restoring the app.
As part of Shopify's security requirements, we are now working closely with them to complete two additional independent security reviews:
- Incident Report (IR): A detailed report explaining the incident, its root cause, impact, and remediation actions.
- Vulnerability Assessment & Penetration Testing (VAPT): An independent security assessment to verify that the application is secure and free from additional vulnerabilities.
We've already engaged a specialized third-party security firm to perform both reviews, and the work is currently underway.
What we ask you to do
Although we have already removed all known malicious scripts from your store, we recommend that you perform a quick verification by:
- Opening your storefront.
- Testing the Add to Cart buttons.
- Testing the Checkout button to confirm it redirects to your normal Shopify checkout.
If you notice any unexpected behavior or have any concerns, please contact our support team immediately. We'll investigate your store with the highest priority.
We sincerely apologize for the inconvenience this incident may have caused. Protecting your store and your customers is our highest priority, and we remain committed to working closely with Shopify to ensure the security of our application.
Contact us
Our support team is ready to assist with any questions or concerns.
If you have any questions or concerns, or notice anything unusual with your store, please reach out — we will respond right away:
Email: contact@qikify.com