u/PromoDiscountsPro

Image 1 — Malicious service worker registered in the browser
Image 2 — Malicious service worker registered in the browser

Malicious service worker registered in the browser

Attention! Even if you changed all passwords, reinstalled WordPress/plugins/themes, and checked both the filesystem and database, don’t forget to check Service Workers in the browsers you use for wp-admin.

I found a heavily obfuscated malicious Service Worker still registered after the site itself was cleaned. It could intercept WordPress login credentials, grab admin nonces, inject code into /wp-admin/, and abuse the authenticated browser session to perform actions such as installing plugins.

The files can be clean while the browser remains compromised.

Check: DevTools → Application → Service Workers.

u/PromoDiscountsPro — 1 day ago