Tech

Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen

Share
Share


  • Researchers found a malicious package on NPM, uploaded a year ago
  • It was benign at first, and introduced malware later via an update
  • The malware stole hundreds of thousands of secrets and installed cryptojackers on dozes of computers

For roughly a year, hackers have been infecting red teamers, penetration testers, security researchers, as well as other hackers, with a piece of malware that steals WordPress credentials and other sensitive data, and installs cryptominers on compromised endpoints.

As a result, login credentials for some 390,000 WordPress accounts were stolen, and dozens of systems were found mining Monero.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find
Tech

Some AI prompts could cause 50 times more CO₂ emissions than others, researchers find

Credit: Sanket Mishra from Pexels No matter which questions we ask an...

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today
Tech

Google Gemini’s super-fast Flash-Lite 2.5 model is out now – here’s why you should switch today

Google’s new Gemini 2.5 Flash-Lite model is its fastest and most cost-efficient...

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up
Tech

5 Nintendo Switch 2 settings I recommend changing as soon as you boot your new console up

There’s nothing quite like the excitement of a new console; feverishly whipping...