logo

Hackers abuse WordPress MU-Plugins to hide malicious code

ID: 894749ee-2988-5942-b083-d2f9cde9ed1c

STIX ID: report--894749ee-2988-5942-b083-d2f9cde9ed1c

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-03-31

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Sucuri researchers report that threat actors are increasingly abusing WordPress mu-plugins (wp-content/mu-plugins/) as a persistent, stealthy foothold to deploy three malicious payload types: a redirector that sends visitors to a fake browser-update page (drive-by malware distribution), a GitHub-backed webshell (index.php / 403WebShell) enabling remote code execution and data theft, and a JavaScript loader that replaces site images with explicit content and hijacks outbound links; site owners are advised to patch plugins/themes, minimize installed components, and protect admin accounts with strong credentials and MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.