This plugin fits the definition of Malware and should be blacklisted.
-
This plugin was randomly installed and activated on every single WordPress site hosted at Siteground. Siteground customers did not consent to the installation of this plugin, nor was the action disclosed by Siteground. The software was added automatically – with AI connectivity – which means it has the ability to perform a stunning amount of damage to individual sites, shared servers, and the Siteground ecosystem as a whole.
Considering AI was not invented by Siteground, that also means it has the ability to contact remote servers controlled by third-parties. The plugin obnoxiously inserts itself into every page on the frontend AND admin panel of every site for administrators – breaking layouts, accessibility, and causing undue hardship to every customer who has to manually purge this MALWARE.
All of this information is factual. Now, read how Cisco – an enterprise leader in IT – says the following classes of malware are DEFINED:
Viruses
A computer virus is a type of malware that propagates by inserting a copy of itself into and becoming part of another program. It spreads from one computer to another, leaving infections as it travels. Viruses can range in severity from causing mildly annoying effects to damaging data or software and causing denial-of-service (DoS) conditions. […] Normally, the host program keeps functioning after it is infected by the virus. However, some viruses overwrite other programs with copies of themselves, which destroys the host program altogether. Viruses spread when the software or document they are attached to is transferred from one computer to another using the network, a disk, file sharing, or infected email attachments.
CiscoLet’s see if any of that applies to this plugin, shall we? Here we go:
- Propagates by inserting a copy of itself and becoming part of another program? ✅ Yes.
- Did it spread from one computer/server to another, leaving infections as it went? ✅ Yes.
- Did it cause mildly annoying effects, damage data, or cause a denial-of-service? ✅ Yes.
- Does the AI in this plugin have the ability to overwrite or destroy other programs? ✅ Yes.
Okay, so the plugin – at the very least – loosely fits the definition of a virus. Let’s move on to the next one:
Worms
Computer worms are similar to viruses in that they replicate functional copies of themselves and can cause the same type of damage. In contrast to viruses, which require the spreading of an infected host file, worms are standalone software and do not require a host program or human help to propagate. To spread, worms either exploit a vulnerability on the target system or use some kind of social engineering to trick users into executing them. A worm enters a computer through a vulnerability in the system and takes advantage of file-transport or information-transport features on the system, allowing it to travel unaided. More advanced worms leverage encryption, wipers, and ransomware technologies to harm their targets.
CiscoOkay, more specific… but let’s do the comparison, anyway:
- Similar to a virus because it replicated itself and can cause the same type of damage? ✅ Yes.
- Did the plugin run without requiring the host program or human help to propagate? ✅ Yes.
- Did the plugin exploit a Siteground vulnerability or trick users into executing it? ✅ Yes.
- Did the plugin take advantage of the system’s file-transport features to travel unaided? ✅ Yes.
Not looking good. That said, we have more definitions to cover because it’s ✨Siteground✨ who will surely be allowed to continue this behavior:
Trojans
A Trojan is another type of malware named after the wooden horse that the Greeks used to infiltrate Troy. It is a harmful piece of software that looks legitimate. Users are typically tricked into loading and executing it on their systems. After it is activated, it can achieve any number of attacks on the host, from irritating the user (popping up windows or changing desktops) to damaging the host (deleting files, stealing data, or activating and spreading other malware, such as viruses). Trojans are also known to create backdoors to give malicious users access to the system. Unlike viruses and worms, Trojans do not reproduce by infecting other files nor do they self-replicate. Trojans must spread through user interaction such as opening an email attachment or downloading and running a file from the Internet.
CiscoLet’s see if the good people of Sparta recognize this plugin:
- Harmful piece of software that looks legitimate? — It certainly harmed some users. ✅ Yes.
- Did Siteground trick users into loading and executing it on their systems? ✅ Yes.
- Is the plugin’s AI able to achieve any number of attacks on the host after activating? ✅ Yes.
- Does the plugin have the potential to give malicious users access to the system? ✅ Yes.
- Does the plugin fit the Trojan definition of being unable to self-replicate? 🚫 No.
Phew… close one — the plugin almost fit the definition of a Trojan there. Good thing it has the ability to self-replicate by infecting other files and systems autonomously.
WORDPRESS — DO THE RIGHT THING AND REMOVE THIS PLUGIN FROM THE REPOSITORY. It provides NO value-added after Siteground customers run out of their sample credits. It’s an involuntary cash-grab that doesn’t benefit any WordPress users outside of Siteground’s ecosystem — and even the idea of it offering anything beneficial is highly questionable.
Shame on you, Siteground.
You must be logged in to reply to this review.