Compromised WordPress Sites Stealing Credentials
ID: 71195745-08b0-5781-bf92-81138e765550
STIX ID: report--71195745-08b0-5781-bf92-81138e765550
Feed Name: Zscaler Security Research Blog
This report describes a WordPress compromise campaign that injects obfuscated JavaScript masquerading as benign libraries (e.g., "googleanalytics.js") into site pages to perform two malicious functions: a JavaScript keylogger that records and exfiltrates keystrokes via WebSocket, and an embedded CoinHive cryptocurrency miner. Researchers observed multiple hosting domains (cloudflare.solutions, msdns.online, cdns.ws, cdjs.online) delivering slightly different script variants and a surge of infections after a domain takedown, highlighting ongoing abuse of vulnerable or unpatched WordPress sites and plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
