216.73.217.22

Surge of JavaScript Malware in sites with vulnerable versions of LiteSpeed Cache Plugin

· Published 09/05/2024 15:08 · Modified 09/05/2024 15:24

Export JSON

Essential information

Published
09/05/2024 15:08
Modified
09/05/2024 15:24
Tags
2024-05-04 2024-05-05 2024-05-06 2024-05-07 2024-05-08 2024-05-09 javascript litespeed plugin vulnerability wordpress
Related entities
6 observables, 17 techniques (mitre)

Description

A recent surge of malicious code has been observed targeting websites using vulnerable versions of the Cache for . The malware injects code into critical files or the database, creating unauthorized admin users like 'wpsupp-user.' It exploits the in Cache before version 5.7.0.1, allowing attackers to inject malicious scripts. The malware is often associated with URLs like 'https://dns.startservicefounds.com/service/f.php' and IPs like 45.150.67.235 or 94.102.51.144. Website owners should review installed plugins, update them, and search for suspicious code or users.

External references