Mobile redirect malware associated with tagDiv Composer

Posted in: Newspaper
Post count: 1

I have a newspaper theme, have been using for a few years for my website with no issue until sometime in January. Initially the main site was down for a day or so. While the display on the desktop has no issue now, a malware is acting on a mobile device. Anytime anyone visits the website from any mobile device, the redirect hacking malware becomes active. I checked this issue with my hosting company and I even hired a professional to work on. Both are pointing out it’s related to td composer. My jetpack scan results also indicates td composer as a threat. In fact, once I deactivate td composer plugin, the issue is resolved (no more redirect on mobile) but the landing page gets broken of course. My hosting company suggested that I should consult with the the theme developer. I don’t know what to do. Would you please help me? https://eyeonsligocreek.com/

Post count: 27744

Hello,

Please let me know what theme version you have.
Please update the theme to the latest version 12.6.4.
This malware infects not only theme files but also WordPress files or other plugin files. This malware was not detected only in our theme but also in many other themes and plugins https://www.bleepingcomputer.com/news/security/massive-balada-injector-campaign-attacking-wordpress-sites-since-2017 / -> https://cybernews.com/security/wordpress-malware-epidemic-balada-injector/ -> https://www.geoedge.com/balda-injectors-2-0-evading-detection-gaining-persistence /
You could consider reinstalling the WordPress version, reinstalling the theme, and checking for this plugin wp-zexit.php. It might be wise to inspect via FTP if it doesn’t appear in the WordPress -> Plugins. Additionally, using Wordfence to scan the website and remove unknown users would be prudent.

Thank you!

Viewing 2 posts - 1 through 2 (of 2 total)
The forum ‘Newspaper’ is closed to new topics and replies.