Reading view

Malicious service worker registered in the browser

Attention! Even if you changed all passwords, reinstalled WordPress/plugins/themes, and checked both the filesystem and database, don’t forget to check Service Workers in the browsers you use for wp-admin.

I found a heavily obfuscated malicious Service Worker still registered after the site itself was cleaned. It could intercept WordPress login credentials, grab admin nonces, inject code into /wp-admin/, and abuse the authenticated browser session to perform actions such as installing plugins.

The files can be clean while the browser remains compromised.

Check: DevTools → Application → Service Workers.

submitted by /u/PromoDiscountsPro
[link] [comments]
  •  
❌