• Resolved tjessberger

    (@tjessberger)


    Hi friends,

    In patching up my site today, I found a malicious malware plugin that had been injected into my site. The plugin has an existing page on the WordPress plugin directory, including contributors and a company website. It’s clear that they used pharma malware injection to generate leads for their website.

    Is there a place I can report this to and have it looked into/removed? I have screenshots/URLs.

    Thanks,
    -Tim

Viewing 3 replies - 1 through 3 (of 3 total)
  • Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    While anything is possible, one thing for sure is that your site was compromised.

    Please remain calm and carefully follow this guide.

    When you’re done, you may want to implement some (if not all) of the recommended security measures.

    Please do not post any malware code in these forums. If you are convinced that the plugin was compromised on the WordPress repo, please send the details privately to [email protected] and they can investigate it.

    Thread Starter tjessberger

    (@tjessberger)

    The email address was the only information I actually needed. I had resolved all issues before posting.

    Your “remain calm” comment is both late and condescending.

    Moderator Jan Dembowski

    (@jdembowski)

    Forum Moderator and Brute Squad

    Your “remain calm” comment is both late and condescending.

    My apologies, I wasn’t being condescending at all. It’s a stock reply.

    The email address was the only information I actually needed. I had resolved all issues before posting.

    Hey, that’s great! I’m glad as a volunteer I was able to provide some help.

    Since you’ve gotten what you needed and I don’t want to risk anymore misunderstanding, I’ll just close this topic now.

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Reporting a malicious plugin listed on the WP plugin directory?’ is closed to new replies.