PHP Backdoor Found in WordPress Plugin After Integrity Monitor Flagged File Change
A security tool called MatrixSwarm detected an unexpected file change inside a WordPress plugin directory on a production server, prompting a manual investigation that uncovered a PHP backdoor. The tool did not identify the malware directly but flagged that the plugin no longer matched its previously approved baseline, highlighting a gap that traditional signature-based scanners can miss. MatrixSwarm's WordPress Plugin Guard works by computing SHA-256 hashes of every file in an approved plugin and alerting operators to any additions, deletions, or modifications. The system requires explicit operator approval before trusting any plugin folder, preventing attackers from slipping in malicious code that could be silently absorbed during a routine baseline refresh. The incident underscores how long-installed or forgotten plugins can become security blind spots when familiarity is mistaken for integrity.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in