Researchers identified a WordPress malware operation that injects malicious JavaScript into sites, fingerprints visitors, and presents a counterfeit Cloudflare verification overlay to hijack active administrator sessions. Using same-origin requests and stolen browser-held tokens, the loader silently installs and activates a backdoored plugin called Web Media Optimizer, establishing a hardcoded administrator-login path and persistent copies in the mu-plugins directory.
The implant hides itself and rogue administrator accounts from the WordPress dashboard and REST API, can restore itself after removal, and remotely injects scripts, removes plugins, or alters plugin content. It steals administrator credentials and sessions, WooCommerce order data, and secrets for Stripe, Braintree, Authorize.Net, and AWS; its EtherHiding mechanism retrieves encrypted C2 details from Ethereum smart contracts via public RPC services. Defenders should inspect mu-plugins and wp_options entries beginning with _wm2_; reported delivery domains used IP 46.29.26.20 and nsdrive.net nameservers, although shared infrastructure alone does not establish attribution.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A detection signature for the malicious WordPress must-use plugin was released on June 23, 2026.
A sophisticated malicious WordPress must-use plugin was discovered during a site cleanup in mid-June 2026. The implant concealed itself and rogue administrator accounts, maintained persistence, stole credentials and data, and used Ethereum-based EtherHiding to obtain command-and-control information.
Investigators identified a malicious JavaScript loader platform that abuses active WordPress administrator sessions to upload and activate a backdoored "Web Media Optimizer" plugin. The installed plugin hides from normal plugin listings, creates a persistent must-use copy, provides a hardcoded administrator-login mechanism, and injects remotely supplied scripts into compromised sites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 27 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.