/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Active malware campaign has hijacked thousands of WordPress sites in just 15 days, has spiked to over 5K new infections daily

Active malware campaign uses thousands of WordPress sites to infect visitors  —  15-day-old campaign has spiked in past 48 hours, with >5,000 new infections daily.

Ars Technica Dan Goodin

Context & Ripple Effects

This campaign extends a pattern the coverage has documented for years: in December 2014, the SoakSoak malware swept through 100,000+ self-hosted WordPress sites by exploiting a known flaw in the RevSlider plug-in, and by May 2015 an actively exploited WordPress bug had put millions of sites at risk. The new outbreak differs mainly in velocity — thousands of sites hijacked in 15 days and accelerating past 5,000 daily infections.

What makes the acceleration notable is that these are not zero-days but known-vulnerability compromises of the kind SoakSoak rode, suggesting the same unpatched-plugin long tail keeps being re-harvested. The later AccessPress backdoor disclosures would show the problem running deeper than patching hygiene, into the plug-in and theme supply chain itself.

First-order effects

  • Owners of the thousands of hijacked sites face immediate cleanup and de-indexing risk while their pages serve malware to every visitor — turning each compromised site into an attack vector against its own audience.

Second-order effects

  • WordPress plug-in and theme developers come under pressure to ship patches faster and prove their update channels are clean, since known-vulnerability exploitation at this scale makes laggard vendors the softest entry point.
  • Security vendors and hosting providers gain a sales argument for managed updates and malware scanning aimed at self-hosted WordPress operators who have shown they will not patch on their own.

Third-order effects

  • If each wave finds fresh unpatched sites years apart — SoakSoak in 2014, this campaign in 2015, the later supply-chain backdoors — the structural fix is consolidation toward hosted or auto-updating WordPress deployments, shrinking the self-managed long tail that attackers farm.
  • Repeated compromise waves give regulators and enterprise buyers grounds to treat unmanaged CMS installs as a liability class, pushing WordPress security from site-owner responsibility toward platform-enforced defaults.

The trend: WordPress compromises keep recurring through the same unpatched plug-in and theme layer, steadily eroding the viability of self-managed installs and pushing the ecosystem toward platform-enforced updating.