logo

Compromised WordPress Sites Leaking Credentials

ID: e12b5f76-01ee-59f0-81a3-a0edbfd69395

STIX ID: report--e12b5f76-01ee-59f0-81a3-a0edbfd69395

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler observed a widespread credential-theft campaign targeting WordPress login pages: injected, obfuscated JavaScript (wp.js) intercepts loginform submissions, Base64-encodes credentials and sends them via GET requests to conyouse.com/scr.js; the report lists multiple compromised sites, shows code and network samples, and recommends keeping WordPress instances patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.