Researchers reported attackers are hiding malicious PHP code in WordPress sites’ mu-plugins directory, a location that loads plugins automatically and is often overlooked because entries do not appear in the standard administrative plugin view. In one observed intrusion, a file named wp-index.php in wp-content/mu-plugins/ fetched a second-stage payload from a ROT13-obfuscated URL, giving the attacker persistent access and the ability to execute remote PHP code on the compromised server.
Additional infections linked to the same technique included redirects to fake update pages, website defacement or content replacement, and webshell deployment. The reported impact ranges from remote code execution and privilege escalation to denial of service and full site compromise, prompting defenders to audit the mu-plugins folder, review indicators of compromise, keep WordPress components updated, enforce proper file permissions, and disable in-dashboard file editing in wp-config.php.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Sucuri published research describing attackers abusing WordPress's mu-plugins directory to hide malicious code that loads automatically and is not shown in the standard plugin interface, enabling stealth and persistence on compromised sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceblog.sucuri.net
Open sourceblog.sucuri.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.