

▲ 15 r/Wordpress
Malicious service worker registered in the browser
Attention! Even if you changed all passwords, reinstalled WordPress/plugins/themes, and checked both the filesystem and database, don’t forget to check Service Workers in the browsers you use for wp-admin.
I found a heavily obfuscated malicious Service Worker still registered after the site itself was cleaned. It could intercept WordPress login credentials, grab admin nonces, inject code into /wp-admin/, and abuse the authenticated browser session to perform actions such as installing plugins.
The files can be clean while the browser remains compromised.
Check: DevTools → Application → Service Workers.
u/PromoDiscountsPro — 1 day ago