• apogeeza

    (@apogeeza)


    Malware Warning:
    This plugin may have been compromised (I’m referring to the recent mass-password reset bit.)

    I installed myPortfolio plus on my site via wp-admin/plugin-install.php, but I got interrupted and didn’t get round to creating any content with it, so the plugin remained in an “install only” state. The next day a security email arrived with the notice quoted below.

    It seems the plugin automatically created “JspWebshell 1.2.php” and “Copie de c99.php” in the wp-content folder root and the 2 malware files was detected by Websitedefender. This was also confirmed through a few Google searches that I ran on the file names.

    I urge the author to check and confirm the zip on WordPress.org is verified malware clean.

    WebsiteDefender discovered the following security problem/s:

    Critical severity alerts:
    Malicious file found (JspWebshell 1.2.php – B.C.T JSP web shell v1.2)
    Possible malicious file found (Copie de c99.php – Suspicious PHP Code)
    Medium severity alerts:
    New WordPress plugin installed (myPortfolio Plus)
    WordPress plugin deleted (xxx)
    WordPress plugin deleted (xxx)
    WordPress plugin requires update (xxx)
    Low severity alerts:
    File structure change: 24 files modified
    File structure change: 45 new files found
    Informational alerts:
    File structure change: 6 files deleted

    http://wordpress.org/extend/plugins/my-portfolio-plus/

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)

The topic ‘[Plugin: myPortfolio Plus] Malware detected at install’ is closed to new replies.