logo

Over 6,000 WordPress hacked to install plugins pushing infostealers

ID: 5b46209d-c700-569a-bd77-a33668b65d33

STIX ID: report--5b46209d-c700-569a-bd77-a33668b65d33

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-10-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

WordPress sites have been actively compromised by a ClearFake/ClickFix campaign that installs bogus plugins (often named to resemble legitimate plugins) which inject JavaScript and load scripts (hosted via a Binance Smart Chain contract) to display fake browser/error overlays; victims are tricked into running PowerShell “fix” scripts that deploy information-stealing malware, with GoDaddy and Sucuri reporting thousands of affected sites and observable access logs indicating use of stolen admin credentials for automated plugin installation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.