Fake Browser Updates Targeting WordPress Administrators via Malicious Plugin
Essential information
- Published
- 08/01/2026 11:41
- Modified
- 08/01/2026 12:44
- Tags
- 2026-01-08 browser updates malicious javascript persistence social engineering
- Related entities
- 1 observables, 1 malware
Description
A malicious WordPress plugin named 'Modern Recent Posts' has been discovered, targeting administrators with fake browser update pop-ups. The plugin injects malicious JavaScript from an external domain, only affecting logged-in administrators on Windows machines. The campaign uses social engineering tactics to trick users into downloading potential malware. The plugin includes persistence mechanisms and can self-update. This sophisticated attack demonstrates a focused approach on high-value targets, leveraging trust in security updates to compromise local machines. The malware's stealthy nature and targeted delivery system make it particularly dangerous for WordPress site owners.