Hacker News new | past | comments | ask | show | jobs | submit login
Wordpress.com – Russian malware hidden in home folder (pastebin.com)
5 points by wyhycu on Oct 17, 2023 | hide | past | favorite | 5 comments



In case anyone else is struggling with random Russian casino posts appearing in your wordpress.com website, I found the culprit.

The instance has 2 folders. htdocs & a read-only wordpress folder with sample content with I cannot alter.

The text in the sample matches the spam posts. "./themes/organic-stax/1.4.6.1/demo/default-demo-content.xml: <content:encoded><![CDATA[Имеется множество формальностей, которые приходиться придер..." (see pastebin link for more)

I have shared this with wordpress support and they stopped replying to my emails. Now I have to check and delete any new posts every day.

Will update if wordpress.com finally addresses this.


Update: wordpress.com has removed/replaced the file, it appears. Support case still unaddressed but root problem is solved. No more mystery posts.


I have tried to find this content and could not for some reason.

Can you please try with `curl` command to produce the pastebin output so we can test it from our side?

UPDATE: Never mind, I have found it!


Thanks for the heads up. We have removed this file from the platform for now while we review.


I work at Automattic (but not on WordPress.com) and I've pinged some folks to take a look at this.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: