Tech

Huge cybercrime attack sees 390,000 WordPress websites hit, details stolen

Share
Share


  • Researchers found a malicious package on NPM, uploaded a year ago
  • It was benign at first, and introduced malware later via an update
  • The malware stole hundreds of thousands of secrets and installed cryptojackers on dozes of computers

For roughly a year, hackers have been infecting red teamers, penetration testers, security researchers, as well as other hackers, with a piece of malware that steals WordPress credentials and other sensitive data, and installs cryptominers on compromised endpoints.

As a result, login credentials for some 390,000 WordPress accounts were stolen, and dozens of systems were found mining Monero.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
US asks judge to break up Google’s ad tech business
Tech

US asks judge to break up Google’s ad tech business

Google is facing a demand by the US government to break up...

New method quickly assesses underwater landslide risk for offshore turbines
Tech

New method quickly assesses underwater landslide risk for offshore turbines

Illustration of dynamic forces acting on monopile and tower, and soil-structure interaction....

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle
Tech

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle

Chuwi’s new CoreBook X features Intel i9-13900HK and 32GB RAM No discrete...