Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

WordPress malware campaign hides payloads in Steam profiles

0
Medium
Malwareweb
Published: Mon Jun 01 2026 (06/01/2026, 17:04:16 UTC)
Source: Bleeping Computer

Description

A malware campaign infected nearly 2,000 WordPress websites by hiding command-and-control data within Steam Community profile comments using invisible Unicode characters. The malware decodes these hidden characters to build URLs that serve malicious JavaScript disguised as legitimate libraries, injecting backdoors into WordPress sites. The backdoor accepts base64-encoded PHP code via specially crafted POST requests with a specific authentication cookie, allowing persistent control. Infection vectors are unclear but may include stolen credentials, vulnerable plugins/themes, or supply-chain compromises. Detection is challenging due to evasion techniques like obfuscation, randomized function names, and use of standard WordPress APIs. Site owners should look for suspicious Steam URL references, external JavaScript injections, and unusual outbound connections. Restoration from known good backups is recommended for remediation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 17:18:48 UTC

Technical Analysis

This malware campaign targets WordPress websites by embedding command-and-control data within Steam Community profile comments using six specific invisible Unicode characters. The malware extracts and decodes these hidden characters to reconstruct a payload URL that delivers malicious JavaScript code disguised as legitimate libraries. This code injects a backdoor into infected WordPress sites, which listens for POST requests containing a specific authentication cookie and base64-encoded PHP code, enabling remote code execution. The infection vector is not definitively known but may involve stolen credentials, vulnerable WordPress components, or supply-chain attacks. The malware employs multiple evasion techniques, including obfuscated strings, randomized function names, and use of WordPress APIs to blend with normal site activity. Detection indicators include references to Steam URLs, suspicious JavaScript injections, outbound connections to Steam, and specific authentication cookies in POST requests. Remediation requires thorough cleaning or restoration from backups to prevent reinfection via the backdoor.

Potential Impact

The malware enables attackers to maintain persistent backdoor access to infected WordPress websites, allowing remote execution of arbitrary PHP code. This compromises the integrity and security of the affected sites, potentially leading to further malicious activities such as data theft, site defacement, or use in broader attack campaigns. The use of Steam profiles for command-and-control data obfuscates attacker infrastructure, complicating detection and mitigation efforts. Approximately 1,980 WordPress sites were affected as of the report date.

Mitigation Recommendations

No official patch is available as this is a malware campaign rather than a software vulnerability. Site owners should prioritize restoring affected WordPress sites from known good backups created before the infection date. If restoration is not possible, a thorough manual cleaning is required to remove all malware components and backdoors, as attackers can reinstall malware if any part remains active. Monitoring for suspicious references to Steam Community URLs, unexpected external JavaScript injections, outbound connections to Steam, and POST requests containing the specific authentication cookie or new_code parameter can aid detection. Removing compromised credentials and updating all WordPress themes, plugins, and core software to the latest versions is recommended to reduce infection risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/","fetched":true,"fetchedAt":"2026-06-01T17:18:39.227Z","wordCount":825}

Threat ID: 6a1dbeefe29bf47b501ec589

Added to database: 6/1/2026, 5:18:39 PM

Last enriched: 6/1/2026, 5:18:48 PM

Last updated: 6/1/2026, 6:26:33 PM

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses