i don’t know who needs to hear this, but make sure your wp version is up to date, there are critical security vulnerabilities in the old versions (i was on 4.2 when this happened)

[ad_1]

hey all

today, while i was checking my server i noticed a weird process in the processes list called “linuxsys”. it seemed suspicious (also because it was maxing out my cpu) so i checked where it was coming from. it was apparently a deleted file under /var/tmp, and that confirmed my initial suspicions that this was malware. it was running as the www-data user, so this had to do something with the www-data -> nginx -> php-fpm -> wordpress chain.

after careful investigation, i found a cron job that gets a couple of files and runs this executable (which was a ZEPH coin miner), and i removed the crontab entry. but even after doing so, the process kept spawning. i digged a bit deeper and saw that there was multiple “Akismet” plugins under my wordpress installation, and they were launching the miner as well. i got rid of them and now the problem seems to be gone, i’ll dig a bit deeper to see if there are any other files that got replaced/infected but yeah, this is just your reminder to always update to the latest version lol

[ad_2]

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer