Skip to content

Comment on Ask HN: I can't tell why my site is showing malware warning.parent

Comments

wow this is definitely a hint. The WPEngine guys are looking into it now.

Happened to seven WP sites I maintain. It's a script and someone got into an account. The script finds all .php and .htm files and adds stuff to the top. If you only have wordpress files, it's an easy fix - reset the password and get a different template.

What does the attack do for those who visited the site trying to figure out what was going on?

The malicious script only inserted an iframe with a broken link, so I wouldn't worry to much.

I would still worry a bit. Some hackers will show a broken link if you're accessing a page directly with no referrers, for example. But if you come in with a referrer or from a search engine, then they might return the malware payload.

If a site was showing up recently in our malware list, it's practically certain that an actual user downloaded malware via the site.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.