logo

Compromised WordPress Sites Stealing Credentials

ID: 71195745-08b0-5781-bf92-81138e765550

STIX ID: report--71195745-08b0-5781-bf92-81138e765550

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a WordPress compromise campaign that injects obfuscated JavaScript masquerading as benign libraries (e.g., "googleanalytics.js") into site pages to perform two malicious functions: a JavaScript keylogger that records and exfiltrates keystrokes via WebSocket, and an embedded CoinHive cryptocurrency miner. Researchers observed multiple hosting domains (cloudflare.solutions, msdns.online, cdns.ws, cdjs.online) delivering slightly different script variants and a surge of infections after a domain takedown, highlighting ongoing abuse of vulnerable or unpatched WordPress sites and plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.