Visualização normal

Antes de ontemMalwarebytes
  • ✇Malwarebytes
  • What happens if you visit a WordPress site hacked through wp2shell?
    WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site? Because a hacked website becomes a delivery mechanism for scams, credential theft, malware, and malicious redirects. The wp2shell vulnerabilities are especially concerning because they affect WordPress Core itself, don’t require a
     

What happens if you visit a WordPress site hacked through wp2shell?

21 de Julho de 2026, 11:57

WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?

Because a hacked website becomes a delivery mechanism for scams, credential theft, malware, and malicious redirects.

The wp2shell vulnerabilities are especially concerning because they affect WordPress Core itself, don’t require a malicious or vulnerable plugin, and can be exploited without authentication on vulnerable versions. Experts say the chain can lead to full administrative control of a site and remote code execution with web server privileges, meaning an attacker can change what the site serves to visitors.

And cybercriminals are already doing their dirty work:

“Exploitation activity began within hours of the patch release. Wordfence observed endpoint probing and SQL injection attempts the same evening, and public proof-of-concept code was reported in the days that followed.”

Once attackers control a WordPress site, they rarely stop at defacement. A common next step is to quietly inject JavaScript, redirect visitors to malicious pages, or load content from attacker-controlled infrastructure. That can expose visitors to fake login pages, scam pop-ups, browser-based malware, or drive-by downloads, depending on the attacker’s goals.

The possible harm

This isn’t an exhaustive list, but these are some of the ways visitors to a wp2shell-compromised site could be affected:

  • Credential theft. Attackers can inject fake login forms or iframe-based overlays that imitate Microsoft 365, Google, banking, or social media sign-in pages to steal usernames and passwords.
  • Malware delivery. The site can be turned into a staging point for browser exploitation, malicious downloads, or redirect visitors to malware-hosting pages.
  • Scams and fraud. Visitors may be redirected to fake support pages, fake giveaways, or fraudulent payment prompts.
  • Tracking and profiling. Attackers can use injected scripts to fingerprint visitors, harvest browser details, and track victims across sessions.
  • Search and reputation damage. Search engines and security tools may flag the site, which can expose visitors to warnings and reduce trust long after the initial compromise.

What you can do

Be cautious, even on websites you normally trust. If something looks different from what you’d expect, treat it as a warning sign.

Be especially wary of unexpected login prompts, download requests, and browser warnings. For site owners, it means patching quickly and treating compromise as a possibility, not an edge case.

Keep your operating system, browsers, and security software up to date. Compromised websites can also try to exploit known vulnerabilities on visitors’ devices.

Use an up-to-date, real-time anti-malware solution that can alarm you if a website tries to infect your device.

Pro tip: Use Malwarebytes’  free Browser Guard extension. It uses heuristic detection to identify malicious websites, block scams, and protect against other web-based threats.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

  • ✇Malwarebytes
  • Malware steals Chrome session cookies to take over your accounts
    An email attachment leads to the installation of a malicious Chrome extension. Researchers say it is part of a Windows backdoor delivered via a phishing email. The malware abuses Chrome Native Messaging to move control from the browser into the host system. Its most notable trick isn’t the phishing lure itself, but the way it uses legitimate browser and Windows features to run PowerShell and collect data while staying inside expected workflows. The attack starts with an email attachment disgu
     

Malware steals Chrome session cookies to take over your accounts

26 de Junho de 2026, 09:44

An email attachment leads to the installation of a malicious Chrome extension. Researchers say it is part of a Windows backdoor delivered via a phishing email. The malware abuses Chrome Native Messaging to move control from the browser into the host system. Its most notable trick isn’t the phishing lure itself, but the way it uses legitimate browser and Windows features to run PowerShell and collect data while staying inside expected workflows.

The attack starts with an email attachment disguised as a PDF. The file uses the misleading extension .pfd.js to look like a PDF document, but it’s actually an obfuscated JavaScript file that drops additional files into the temporary folder and starts the rest of the infection chain.

As part of that chain, a PowerShell script prepares a Chrome extension and changes Chrome policy settings so that the extension can be installed. The malware makes the installation appear to be an administrator-controlled deployment rather than a normal extension installation.

Once active, the extension and its native companion collect browser cookies, open tabs, URLs, language settings, and fingerprinting data. The operators also use the setup as a remote command channel, sending instructions that can launch PowerShell and enumerate the contents of the C: drive.

With the stolen authenticated session cookies, the attackers can hijack active browser sessions rather than just stealing passwords, which is more useful to them as it lets them access accounts already logged in on the victim’s browser, bypassing multi-factor authentication (MFA).

The most interesting aspect of the attack is its abuse of Chrome Native Messaging as a bridge between the browser sandbox and the operating system. Chrome allows extensions to communicate with a registered native host, and the attackers weaponized that legitimate feature to make the extension a controller for local code execution. The extension doesn’t launch PowerShell directly. Instead, it sends messages to the native host, which then launches or interacts with PowerShell on the host system.

How to stay safe

The first line of defense against attacks of this kind is to avoid opening email attachments unless you can verify the sender. In addition:

  • Always check the real file extension instead of relying on the displayed filename.
  • Use an up-to-date, real-time anti-malware solution to detect and block malicious activity.
  • Check the installed Chrome extensions on your device and remove any you don’t recognize or no longer use.
  • To be extra cautious, sign out of important accounts when you’re finished. That invalidates your session, so even if someone has stolen your session cookie, they won’t be able to use it to access your account.
  • Regularly check the login history for important accounts. Many online services let you see which devices have signed in, when, and from where.

IOCs

Attachment:

Fattura-2819889242.pfd.js (displayed as Fattura-26189991026.pdf)

Malicious files:

client_124578.exe
d3d11.dll

Chrome extension:

Name: Cloud vn105rkj64
ID: gghagmhimhgfeajfdmjkgmmehbokmglg

Domain:

ext2[.]info

This is blocked by Malwarebytes Browser Guard, our free browser extension that blocks ads, trackers, malware, and more.

Browser Guard blocks ext2[.]info
Browser Guard blocks ext2[.]info

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

❌
❌