GoDaddy researchers uncovered a malware campaign affecting nearly 2,000 WordPress sites that uses Steam Community profile comments as a covert command-and-control channel. The malware stores payload data in benign-looking comments with invisible Unicode characters, decodes that content when a page loads, and builds a URL to fetch malicious JavaScript from hello-mywordl[.]info. The retrieved code is disguised as legitimate JavaScript libraries and injected into WordPress frontend pages, allowing attackers to deliver malicious content while blending in with normal site behavior.
Researchers said the campaign also installs a final-stage PHP backdoor that enables remote code execution through crafted POST requests and an authentication cookie. The initial intrusion vector remains unknown, but possible paths include stolen WordPress admin or FTP/SFTP credentials, vulnerable themes or plugins, or a supply-chain compromise. The malware uses string obfuscation, randomized function names, fake disabled logging, and abuse of standard WordPress APIs to evade detection, and GoDaddy warned that incomplete remediation can let attackers regain access unless affected sites are restored from a known-good backup.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
GoDaddy Security said it first detected the WordPress malware campaign in July 2025. The campaign later grew to affect about 1,980 WordPress sites and used Steam Community profile comments with invisible Unicode characters to conceal command-and-control data.
GoDaddy researchers reported a malware campaign affecting nearly 2,000 WordPress websites that abuses Steam Community profile comments as a covert command-and-control channel. The malware decodes payload data hidden with invisible Unicode characters, retrieves malicious JavaScript from hello-mywordl[.]info, and deploys a PHP backdoor enabling remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcexakep.ru
Open sourcesecurityonline.info
Open sourcehackread.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcegodaddy.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.