logo

Hackers deploy crypto drainers on thousands of WordPress sites

ID: 551ca454-8283-555a-88e3-1934c8ef71c4

STIX ID: report--551ca454-8283-555a-88e3-1934c8ef71c4

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Security firms report that threat actors have compromised approximately 1,000–2,000 WordPress sites and are loading malicious scripts from dynamic-linx.com which randomly display fake NFT and discount pop-ups to trick visitors into connecting crypto wallets; once connected, the crypto drainers steal funds and NFTs. The scripts check for a specific cookie ("haw"), support MetaMask, WalletConnect and other wallets, and have been observed across over 2,000 sites in the past week.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.