Advanced Malware Campaign Targets WordPress and WooCommerce Sites with Obfuscated Skimmers

A sophisticated malware campaign is currently targeting WordPress and WooCommerce websites, deploying highly obfuscated credit card skimmers and credential theft tools, marking a significant escalation in e-commerce cyber threats.
This malware family showcases advanced technical sophistication through its modular architecture, featuring various variants aimed at payment data theft, WordPress credential harvesting, and fraudulent advertising injection.


Notably, it employs anti-analysis measures typical of advanced persistent threats, such as developer tools detection and console rebinding, allowing attackers to seamlessly integrate malicious functions into legitimate checkout processes.
The operational timeline indicates ongoing development and deployment activities since September 2023, suggesting a well-resourced threat actor capable of long-term operations. The malware cleverly avoids detection by limiting execution to specific areas of websites, using cookies to identify site administrators, and employing sophisticated targeting mechanisms to maximize data collection while remaining covert.


Wordfence researchers identified this malware during a routine site cleanup on May 16, 2025, uncovering a complex infrastructure supporting multiple attack vectors across numerous compromised sites. Alarmingly, the malware is packaged as a rogue WordPress plugin, creating persistent infrastructure on victim websites and enabling distributed command and control capabilities while masquerading as legitimate functionality.
The malware's advanced anti-analysis techniques include debugger traps and infinite loops designed to disrupt debugging efforts, showcasing a level of sophistication rarely seen in commodity malware campaigns targeting e-commerce platforms.
- Other (43)
- Ransomware (153)
- Events and News (27)
- Features (45)
- Security (484)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (49)
- Malware Alerts (228)
- Cyber Attack (291)
- Data Backup (13)
- Data Breach (122)
- Phishing (163)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (70)
- Android Security (75)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (68)
- Social Media (8)
- vulnerability (69)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (9)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (6)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (32)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (20)