WordPress websites have become a prime target for malicious actors seeking to exploit traffic and compromise visitor security.
See also: Sophisticated malware campaign targets WordPress websites

In recent months, a new malicious advertising campaign has emerged that leverages silent PHP code injections within theme files to serve unwanted third-party scripts. The attack integrates seamlessly with legitimate website functionality, delivering obfuscated JavaScript that redirects visitors, displays pop-ups, and evades security tools without arousing suspicion.
The breach was initially discovered by a website owner who noticed unexplained script loading. The attack originated from a small block of PHP code added to the functions.php . This injection did not change the visible content of the page, but ran in the background on every request.
See also: WordPress: Critical vulnerability in Case Theme User plugin

Sucuri analysts discovered the campaign after detecting anomalous JavaScript calls to domains controlled by attackers and the exclusive list of multiple security vendors. The attack primarily exploits weak file permissions and outdated themes. By gaining write access—often through compromised credentials or vulnerable plugins—hackers inject a seemingly harmless function that communicates with a command-and-control server.
Once triggered via wp_head, the function retrieves a dynamic payload and replays it in the page section, ensuring execution before the rest of the page loads. Sucuri researchers noted that the injection function creates a POST connection to a remote point at hxxps://brazilc[.]com/ads.php, retrieves the malicious script, and embeds it directly into the HTML document.
The payload performs two main actions: it loads a traffic distribution script from porsasystem.com/6m9x.js and injects a hidden 1×1 pixel iframe that mimics Cloudflare’s challenge platform. These techniques allow for forced redirects, pop-ups, and security scanner evasion by disguising malicious activity as legitimate CDN operations.
See also: Hackers actively exploit critical RCE in WordPress Alone

The infection mechanism is based on the following PHP function inserted in functions.php: On each page load, this function is silently executed, contacting the C&C server and printing the returned JavaScript payload in the page header. The attacker's script then loads further malicious code asynchronously, leveraging attributes such as data-cfasync='false' and async to bypass the Cloudflare Rocket Loader. By embedding itself inside a hidden iframe, the malware evades detection and remains persistent until the injected code is removed.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
