/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Active malware campaign has hijacked thousands of WordPress sites in just 15 days, has spiked to over 5K new infections daily

Dan Goodin / Ars Technica :

Ars Technica Dan Goodin

Context & Ripple Effects

The 15-day infection wave is the latest chapter in a pattern Ars has tracked since at least December 2014, when the [[a:824546|SoakSoak malware infected more than 100,000 self-hosted WordPress sites through a known RevSlider plug-in flaw]]. Five months before this campaign, researchers flagged an actively exploited WordPress bug putting millions of sites at risk.

What makes the current spike notable is velocity rather than novelty: over 5,000 new infections a day against a platform whose long tail of self-hosted installs and third-party plug-ins repeatedly fails to patch known vulnerabilities — the same gap later exploited by backdoor admin accounts ([[a:939802]]) and the AccessPress theme-and-plug-in backdoors.

First-order effects

  • Thousands of site owners face cleanup on compressed timelines — removing injected code, resetting credentials, and restoring from backups — while their visitors are served malicious content in the interim.
  • Hosting providers absorbing the traffic and abuse reports must quarantine infected accounts or risk their own IPs and shared infrastructure being flagged.

Second-order effects

  • Security firms and managed-hosting rivals gain a sales opening: every wave like this pushes non-technical owners toward paid services that apply plug-in patches automatically instead of relying on manual updates.
  • Plug-in and theme developers come under renewed pressure to ship fixes faster, since unpatched extensions — as SoakSoak showed with RevSlider — become the attack surface for the entire installed base.

Third-order effects

  • If the cycle repeats — known vulnerability, slow tail-end patching, mass automated compromise — self-hosting drifts toward managed platforms and hardened distributions, consolidating WordPress deployment around providers who patch centrally rather than millions of individually maintained installs.
  • Regulators and payment networks increasingly treat compromised sites as a systemic problem rather than isolated incidents, raising the compliance bar for small operators who cannot demonstrate timely patching.

The trend: WordPress's vast plug-in-dependent install base keeps turning individual unpatched vulnerabilities into industrial-scale malware campaigns, steadily shifting hosting toward centrally patched, managed environments.