Thousands of WordPress sites have been hacked to install malicious plugins that display fake software updates and errorsto promote info-stealer malware.

This type of malware is very dangerous, as the stolen credentials are used to compromise networks and steal data. Since 2023, a malicious campaign called ClearFakehas been displaying fake banners with alleged browser updates on compromised websites. The goal is to trick users into trying to update their browser and eventually getting infected with malware.
In 2024, a new campaign called ClickFix, displaying software error messages and urging users to fix the problem. However, these “fixes” are PowerShell scripts that, when executed, will download and install info-stealer malware.
See also: LiteSpeed Cache WordPress: New vulnerability allows XSS attacks
Researchers have observed ClickFix campaigns that hack websites to display fake errors for Google Chrome, Google Meet, Facebook , and more.
Malicious WordPress plugins
Last week, GoDaddy reported that cybercriminals have compromised over 6,000 WordPress websites to install malicious plugins that display fake alerts related to the ClearFake/ClickFix campaigns.
“The GoDaddy Security team is tracking a new variant of the ClickFix (also known as ClearFake) campaign with fake browser updates, distributed via fake WordPress plugins,” explains GoDaddy security researcher Denis Sinegubko.
“These seemingly legitimate plugins are designed to appear harmless to website administrators, but they contain embedded malicious scripts that deliver fake browser update messages to end users“.
Malicious plugins use names similar to legitimate plugins, such as Wordfense Security and LiteSpeed Cache.
Η λίστα των κακόβουλων plugins που εμφανίζονται σε αυτήν την καμπάνια (μεταξύ Ιουνίου και Σεπτεμβρίου 2024) είναι:
| LiteSpeed Cache Classic | Custom CSS Injector |
| MonsterInsights Classic | Custom Footer Generator |
| Wordfence Security Classic | Custom Login Styler |
| Search Rank Enhancer | Dynamic Sidebar Manager |
| SEO Booster Pro | Easy Themes Manager |
| Google SEO Enhancer | Form Builder Pro |
| Rank Booster Pro | Quick Cache Cleaner |
| Admin Bar Customizer | Responsive Menu Builder |
| Advanced User Manager | SEO Optimizer Pro |
| Advanced Widget Manage | Simple Post Enhancer |
| Content Blocker | Social Media Integrator |
Website security company Sucuri reported a fake plugin called “Universal Popup Plugin” that is also part of this campaign.
See also: Security vulnerabilities in Houzez WordPress Theme and Plugin
Once installed, the malicious plugin will do several things to inject a malicious JavaScript script into the website's HTML. When loaded, this script will attempt to load an additional malicious file , which then loads the ClearFake or ClickFix script to display the fake updates/errors.
It appears that initially the attackers use stolen administrator credentials to log in to WordPress sites and install the plugin in an automated manner.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Once they log in, the attackers upload and install the malicious plugin.
WordPress site administrators should be very careful and check for user reports of update notifications. They should check the list of installed plugins and remove any that are not installed by the administrators. If unknown plugins are found, it is also recommended to immediately reset the passwords for the admin users.

Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
See also: WordPress will require 2FA from plugin developers
Securing your website is also important for maintaining the consistency and credibility of content your. If a hacker breaks into your WordPress site and corrupts the content, it can give the impression that you don't care enough about your website.
In other words, ensuring your WordPress website is secure isn’t just about protecting your data – it’s about maintaining your customers ’ trust , preserving your company’s reputation, and staying on top of the competition.
Source: www.bleepingcomputer.com
