logo

WordPress malware campaign hides payloads in Steam profiles

ID: d7506b09-52c1-5f5b-a6b8-7d2bb958318d

STIX ID: report--d7506b09-52c1-5f5b-a6b8-7d2bb958318d

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-06-01

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Nearly 2,000 WordPress sites were infected by a campaign that hides C2 data in Steam Community comments using invisible Unicode characters; the compromised sites fetch obfuscated JavaScript from hello-mywordl.info masquerading as legitimate libraries and deploy a PHP backdoor that accepts base64-encoded payloads when a specific authentication cookie is present.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.