Skip to content
WordPress careClient work, anonymised

Hacked-site cleanup for a web agency

Work done for a partner agency, including malware that kept reinstalling itself from the database and cache, and a Web3 card skimmer.

The challenge

A partner agency's WordPress sites were hacked, and on some of them the malware came back after it was removed. The attacks were built to stay hidden: a plugin that hid itself from the admin, fake admin accounts using the site's own domain, scripts shown only to visitors and never to logged-in admins, and code stored in the database instead of in files.

What we built

Each site was fully backed up before anything was changed, with samples of the malware kept as evidence. We removed hidden plugins, web shells, fake admin accounts and server jobs that put the malware back every few minutes. On the worst site, the malware lived in the database and rewrote its files within minutes of being deleted, so it was cleaned from the database as well. Core files, themes and plugins were checked against the official wordpress.org packages, every admin account was listed and checked by hand, and every login was signed out. Each cleaned site was then loaded repeatedly and scanned again, to confirm nothing came back.

Project facts

Type
Client work, anonymised
Platforms
WordPress
Technology
  • WP-CLI
  • SSH
  • wordpress.org checksums
  • MySQL
  • shell scripts

Result

34+ sites audited, 14 infected sites cleaned, 7 types of malware removed.

WordPress careCleanup, maintenance and security

Is your site hacked or at risk?

Describe it in a short form. You'll get a written plan and a fixed quote first.

Get a quote