I have noticed that on some of our Internet sites that use “tagDiv Composer” you are being diverted to other Internet sites that contain malware.
I have reported the problem to our provider (SiteGround) and they have noticed that the problem no longer occurs if the “tagDiv Composer” plugin is disabled.
Please check the code of “tagDiv Composer”.
Best regards.
-
This topic was modified 2 years by
Marco Calvo.
Hello,
Please let me know what theme version you have.
Please update the theme to the latest version 12.6.2.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.
Thank you!
I did everything you recommended, unfortunately, however, the problem was not solved.
Yes, I reinstalled WordPress, checked for unauthorized users, checked plugins, etc. Everything seems OK, but you still get hijacked occasionally to other sites.
Why isn’t a tool released that checks all the problems caused by the “tadDIV Composer” plugin? So many Internet sites have been damaged because of the incorrect design of this plugin.
Yes, I use both WordFence and the antivirus provided by SiteGround. But these tools are not reliable. Both say everything is OK, unfortunately, however, every now and then some users get hijacked to pornographic sites or sites containing malware. Perhaps the new version of tagDIV Composer also contains vulnerabilities.
Hi,
What plugins do you have? Maybe there are vulnerabilities -> https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/
Thank you!
Hello Anamaria/tagdiv team,
I wanted to inform you that the same issue has occurred. I reported it to SiteGround, and they mentioned that there seems to be an issue within the theme itself—a malware presence in the database is causing unwanted redirects to other sites, classifying it as adware. Users are experiencing unwanted pop-ups and redirections when visiting our site. Specifically, there is a row in the wp-option td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.
Furthermore, there’s a problem with updating my theme to version 12.6.2. Whenever I attempt the update, it redirects me to the Dashboard instead of completing the process. Could you please assist me in understanding why this is happening? Your help would be greatly appreciated.
Hello,
Please try to update the theme manually via FTP -> https://forum.tagdiv.com/how-to-update-the-theme-2/
Thank you!
Thanks for the suggestion, but the theme is up to date. Yet there continue to be problems. I would be happy if you found a more effective solution, making a greater effort to solve a very serious problem. I also say this in your interest, I will not be able to advise my clients to adopt your themes if you do not solve these serious security issues. And maybe other web agencies will behave the same way too (if you do a search online, many users are complaining).
-
This reply was modified 2 years by
Marco Calvo.
Hi,
We solved and we added in every update improvements for security. If you want, we can take a look, please contact us via email at contact@tagdiv.com and provide the wp-admin and cPanel access.
Thank you!
@anamaria several of us have the same problem. So apparently there is a big problem here that needs to be addressed. Many of us have sent you emails about this and have not gotten a response. It’s been over a week for me and you all have complete access to everything right now. Perhaps it’s time to listen to your customers and figure out what’s causing this error rather than tell people to update and then try it. It’s been well over 6 weeks that I’ve been dealing with this. I am about to lose my entire business because of this.
Dear Anamaria, you keep writing that you have solved the problem and we keep telling you that instead the problem has not been solved. How can we get through this stage? Is there any hope that you will listen to your users and finally commit to really solving the problem?
Hello everyone,
I managed to resolve this issue manually. Please follow the steps below to help address the malware problem:
Step 1: Identification
Firstly, locate the malware within the database. Look for a row in the wp-option table named td_live_css_local_storage that contains JavaScript code resembling fast.quickcontentnetwork.com within the option value.
Step 2: Backup
Ensure you create a backup of your current site or application.
Step 3: Deactivate td-composer
Deactivate td-composer and proceed to delete it.
Step 4: Download the Newspaper zip file
Unzip and manually upload the plugin from the following path – Newspaper-tf > plugins > td-composer. If the issue persists, proceed to step 5.
Step 5: Manual Theme Reinstallation
Remove the theme from the server. Navigate to public_html > wp-content > themes and delete the “Newspaper” folder.
Step 6: Reinstall the Theme
Head to the WordPress dashboard, navigate to Appearance > Themes, click on Add New Theme, and install the theme.
Following these steps should help resolve the malware issue. Feel free to provide any feedback or if you need further assistance.
Thank you Ganuk007,
I found the malware in the td_live_css_local_storage table. Do we need to delete all the content of the field or just the string:
(/style)(script src="https://fast.quickcontentnetwork.com")(/script)(style)
Hello Marco Calvo,
Attempting to delete that field won’t work; it won’t delete. If you try to delete it, it will automatically regenerate as it’s a Balada Malware Injector.
Therefore, you’ll need to reinstall the theme manually. Follow Step 5 & Step 6 as outlined above. & Before this don’t forget Step 2: Backup
Hopefully, this will work for you.
I have noticed this in the server, we have continuous visits from ips from rumania and netherlands asking for “/wp-json/tdw/save_css”. Fortunately this petitions are resolve with 403 instead this ips are not blocked. Look the screenshot: https://ibb.co/SnpVDsL
This happened months ago too. A code was inserted in template css and javascripts options boxes when you look there. Then you update the theme, and it seems that petition to be solved with a 403. It seemed they (I mean the hackers) disappears but since a couple of weeks I have noticed they are asking for CSS again because they know you have a vulnerability there. Today they are asking without stops, sometimes more than 50 times per minute…
Someone is attacking your theme without stop. You should take a look to this issue. Right now, fortunately, I have not been injected but they could find a new way again. This is a long-standing problem.
-
This reply was modified 2 years by
loslunes.
I received this message from TagDiv support. Let’s hope it works:
Hi,
That is indeed the malware – https://labs.sucuri.net/blacklist/info/?domain=fast.quickcontentnetwork.com I found it as well on a few websites while I was investigating similar issues. Checking in the Live CSS option is a very important step in cleaning the malware, I’m not sure my colleagues from the forum didn’t mention it. We added a filter for the Live CSS in newer theme versions, which doesn’t allow malware to be entered there anymore. But if the website was infected while using an older theme version, updating the theme doesn’t solve the problem. What you have to do after updating the theme is open the Live CSS and press save – https://prnt.sc/a4XFrTI5j9tb That is it, the malware will be removed from there.
But I would still have a few suggestions based on what I encountered in other cases:
– In case you have not already, check in the plugins folder using a file manager (cPanel, FTP, etc.) to see if there are plugins there which you did not install. The plugins may not show up in wordpress but they could be there.
– Scan the website with wordfence.
– Check the website users.
The website does appear to be clean now – https://sitecheck.sucuri.net/results/https/www.marcocalvo.it There’s nothing in the Live CSS and no unusual scripts loading. If I can help with something let me know.
Regards.
I’m facing the same issue. A sudden spike in traffic due to malware has happened. The site is showing 525 and 500 errors. Hosting people are helpless and tried every way possible they are asking to raise issues in the forum. The complete issue is due to tagdiv plugins.
If someone has figured the way out kindly help me with this it’s been a week and I’m frustrated.