Cybersecurity researchers have discovered a highly advanced malware campaign targeting WordPress websites, capable of stealing credit card details, user logins, and even profiling victims.
Discovered on May 16, 2025, by the Wordfence Threat Intelligence Team, this malware is packaged as a deceptive WordPress plugin and uses never-before-seen anti-detection methods. A particularly innovative tactic involves hosting a live management system directly on the infected websites, making it harder to spot.
Källa: New WordPress Malware Hides on Checkout Pages and Imitates Cloudflare
