Swarms of Fake WordPress Plug-ins Infect Sites With Infostealers
ID: aebb8185-ad02-50db-b501-567b4f594fe0
STIX ID: report--aebb8185-ad02-50db-b501-567b4f594fe0
Feed Name: Dark Reading
Date Published: 2024-10-22
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
GoDaddy and other researchers observed a large-scale ClickFix campaign in which attackers used stolen WordPress credentials to install bogus plugins that inject JavaScript to display fake browser update prompts; those prompts use blockchain/smart-contract mechanisms to fetch and deliver infostealers and other malicious payloads. The campaign is automated—threat actors systematically generate plausible plugin metadata and file names to scale infections across thousands of sites (reported >6,000 in a single day and >25,000 observed)—and GoDaddy published IoCs to help defenders identify compromised sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
