
WordPress Service Worker Uses EtherHiding, ClickFix and Steganography to Deploy Amatera Stealer
The campaign has affected hundreds of WordPress websites. Attackers plant a rogue must-use plugin, named in the format site-helper-<hex>, that loads automatically with the site. The plugin registers a malicious Service Worker in a visitor’s browser, allowing the attackers to retain control beyond the initial webpage visit. The Service Worker intercepts page requests, removes Content-Security-Policy […]
The post WordPress Service Worker Uses EtherHiding, ClickFix and Steganography to Deploy Amatera Stealer appeared first on Cyber Security News.