Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

WordPress malware campaign hides payloads in Steam profiles

0
Medium
Malwareweb
Published: 06/01/2026 (06/01/2026, 17:04:16 UTC)
Source: Bleeping Computer

Description

Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 17:18:48 UTC

Technical Analysis

This malware campaign targets WordPress websites by embedding command-and-control data within Steam Community profile comments using six specific invisible Unicode characters. The malware extracts and decodes these hidden characters to reconstruct a payload URL that delivers malicious JavaScript code disguised as legitimate libraries. This code injects a backdoor into infected WordPress sites, which listens for POST requests containing a specific authentication cookie and base64-encoded PHP code, enabling remote code execution. The infection vector is not definitively known but may involve stolen credentials, vulnerable WordPress components, or supply-chain attacks. The malware employs multiple evasion techniques, including obfuscated strings, randomized function names, and use of WordPress APIs to blend with normal site activity. Detection indicators include references to Steam URLs, suspicious JavaScript injections, outbound connections to Steam, and specific authentication cookies in POST requests. Remediation requires thorough cleaning or restoration from backups to prevent reinfection via the backdoor.

Potential Impact

The malware enables attackers to maintain persistent backdoor access to infected WordPress websites, allowing remote execution of arbitrary PHP code. This compromises the integrity and security of the affected sites, potentially leading to further malicious activities such as data theft, site defacement, or use in broader attack campaigns. The use of Steam profiles for command-and-control data obfuscates attacker infrastructure, complicating detection and mitigation efforts. Approximately 1,980 WordPress sites were affected as of the report date.

Mitigation Recommendations

No official patch is available as this is a malware campaign rather than a software vulnerability. Site owners should prioritize restoring affected WordPress sites from known good backups created before the infection date. If restoration is not possible, a thorough manual cleaning is required to remove all malware components and backdoors, as attackers can reinstall malware if any part remains active. Monitoring for suspicious references to Steam Community URLs, unexpected external JavaScript injections, outbound connections to Steam, and POST requests containing the specific authentication cookie or new_code parameter can aid detection. Removing compromised credentials and updating all WordPress themes, plugins, and core software to the latest versions is recommended to reduce infection risk.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/wordpress-malware-campaign-hides-payloads-in-steam-profiles/","fetched":true,"fetchedAt":"2026-06-01T17:18:39.227Z","wordCount":825}

Threat ID: 6a1dbeefe29bf47b501ec589

Added to database: 06/01/2026, 17:18:39 UTC

Last enriched: 06/01/2026, 17:18:48 UTC

Last updated: 07/23/2026, 13:08:13 UTC

Views: 169

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses