logo

Over 5,000 WordPress Sites Infected with Keylogger

ID: 5d3ab66c-2426-5a55-8781-f3777a408e24

STIX ID: report--5d3ab66c-2426-5a55-8781-f3777a408e24

Feed Name: Binary Defense Blog

Threat Score
70/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Security researchers observed that more than 5,000 WordPress sites were infected by a malware tracked as “Cloudeflare.solutions,” which initially performed cryptomining and has been updated to include a keylogger. The malware injects code into themes' functions.php, uses counterfeit Cloudflare-like domains to deliver payloads, aims to harvest login credentials and target e-commerce platforms for banking fraud, and defenders are advised to remove the malicious add_js_scripts function and related add_action clauses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.