Malware?
-
Hi, a customer told me yesterday morning that SPAM messages appeared on the home page of his site.
The problem occurred only on devices NOT connected to wifi (and not on all), therefore only in mobile data mode.
I tried to scan wordpress with wordfence, with sitecheck.sucuri.net and verified that there were no alerts in the google search console. The filters in my hosting were also active and reported nothing. On the desktop the problem did not occur, and there was no trace of calls to unknown URLs.Checking the files I found two files, helad.php and admin_ips.txt in the plugins folder. The code of the first file refers to the second and there are references to urls of SPAM sites, such as topflownews.
Deleting these files the problem did not recur.
So I looked for a reference to this file in the code of all the installation files and found it only in the analysis-1420.js file present in the js folder in the yoast wordpress-seo folder.I re-downloaded the plugin from the www.remarpro.com repository and compared the file that was on my server with the “official” one just downloaded with Kaleidoskope (mac) and they are identical.
At the moment for safety I have deleted the yoast folder.Keep in mind that the problem occurs only in mobile data mode, and since in many countries there is still the lockdown many may not have noticed the problem using mainly with the wifi
can you check that js?
thanks
- The topic ‘Malware?’ is closed to new replies.