Over 6,000 WordPress hacked to install plugins pushing infostealers
ID: 5b46209d-c700-569a-bd77-a33668b65d33
STIX ID: report--5b46209d-c700-569a-bd77-a33668b65d33
Feed Name: Bleeping Computer
WordPress sites have been actively compromised by a ClearFake/ClickFix campaign that installs bogus plugins (often named to resemble legitimate plugins) which inject JavaScript and load scripts (hosted via a Binance Smart Chain contract) to display fake browser/error overlays; victims are tricked into running PowerShell “fix” scripts that deploy information-stealing malware, with GoDaddy and Sucuri reporting thousands of affected sites and observable access logs indicating use of stolen admin credentials for automated plugin installation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
