Title: Alleged malicious code
Last modified: August 22, 2016

---

# Alleged malicious code

 *  Resolved [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/)
 * Got this a few days ago from my host:
 * This notice is to inform you that we have detected malicious code in your website
   files. We have compiled a list of compromised files on your account, as well 
   as the code injected, below.
 * In order to maintain a secure hosting environment, we will be automatically correcting
   these compromised files on your account; however, please be aware that you are
   responsible for verifying that the content hosted within your account is secure.
   We strongly advise that you update your installed scripts and software, as outdated
   scripts and software are the most frequently used method for accessing and gaining
   control of a targeted account.
 * If you need assistance updating the software on your hosting account, please 
   do not hesitate to contact our Support department.
 * The compromised files detected are:
 * /home4/mademer1/public_html/globalindieauthor/wp-includes/js/tinymce/utils/ossdl-
   cdn.php
 * The malicious code detected is similar to:
 * Files with the following contents or MD5SUMs, which contain malicious code:
    \
   $default_action\s*=\s*[‘”]FilesMan[‘”]\s*
 * When I check the directory, the ossdl-cdn.php is absent. So I cannot tell if 
   my host removed it because “we will be automatically correcting these compromised
   files on your account” or because the files are hidden.
 * I have looked this up and there are several examples of the same warning from
   one’s host provider but each time the alleged offending file is different.
 * Any ideas as to how I can verify and remove this code?
 * Thanks.

Viewing 6 replies - 31 through 36 (of 36 total)

[←](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
[1](https://wordpress.org/support/topic/alleged-malicious-code/?output_format=md)
[2](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
3

 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757273)
 * At the very least, I’m glad it’s under control now. 🙂
 *  Thread Starter [Bad_Egg](https://wordpress.org/support/users/bad_egg/)
 * (@bad_egg)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757274)
 * Yes, and thank you again for your help and patience.
 *  Moderator [James Huff](https://wordpress.org/support/users/macmanx/)
 * (@macmanx)
 * [11 years, 6 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757275)
 * You’re welcome!
 *  [stbedesantafe](https://wordpress.org/support/users/stbedesantafe/)
 * (@stbedesantafe)
 * [11 years, 4 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757364)
 * I’ve had this issue for the past 2 months. My host states that plugins are the
   main culprit for allowing malicious code to be slipped into a site’s files. My
   most recent encounter pointed to Jetpack, so I’ve deleted that plugin.
 *  [Andrew Nevins](https://wordpress.org/support/users/anevins/)
 * (@anevins)
 * WCLDN 2018 Contributor | Volunteer support
 * [11 years, 4 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757365)
 * [@stbedesantafe](https://wordpress.org/support/users/stbedesantafe/), It’s unlikely
   you’re experiencing the same issue.
 *  [stbedesantafe](https://wordpress.org/support/users/stbedesantafe/)
 * (@stbedesantafe)
 * [11 years, 4 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757366)
 * The report contained the following:
 * The malicious code detected is similar to:
 * Files with the following contents or MD5SUMs, which contain malicious code:
 * \$default_action\s*=\s*[‘”]FilesMan[‘”]\s*

Viewing 6 replies - 31 through 36 (of 36 total)

[←](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
[1](https://wordpress.org/support/topic/alleged-malicious-code/?output_format=md)
[2](https://wordpress.org/support/topic/alleged-malicious-code/page/2/?output_format=md)
3

The topic ‘Alleged malicious code’ is closed to new replies.

## Tags

 * [remove](https://wordpress.org/support/topic-tag/remove/)

 * In: [Fixing WordPress](https://wordpress.org/support/forum/how-to-and-troubleshooting/)
 * 36 replies
 * 5 participants
 * Last reply from: [stbedesantafe](https://wordpress.org/support/users/stbedesantafe/)
 * Last activity: [11 years, 4 months ago](https://wordpress.org/support/topic/alleged-malicious-code/page/3/#post-5757366)
 * Status: resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
