Compromised WordPress Sites Leaking Credentials
ID: e12b5f76-01ee-59f0-81a3-a0edbfd69395
STIX ID: report--e12b5f76-01ee-59f0-81a3-a0edbfd69395
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler observed a widespread credential-theft campaign targeting WordPress login pages: injected, obfuscated JavaScript (wp.js) intercepts loginform submissions, Base64-encodes credentials and sends them via GET requests to conyouse.com/scr.js; the report lists multiple compromised sites, shows code and network samples, and recommends keeping WordPress instances patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
