Skip to content

Instantly share code, notes, and snippets.

@tomasdev
Last active October 27, 2017 18:11
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save tomasdev/b526c5ddfa06a417297012d6a46b36b0 to your computer and use it in GitHub Desktop.
Save tomasdev/b526c5ddfa06a417297012d6a46b36b0 to your computer and use it in GitHub Desktop.
https://files.fm/u/u7x6q9t7 IS A VIRUS wp-gif-player download link

BEWARE https://files.fm/u/u7x6q9t7 THIS IS A VIRUS FOR WORDPRESS. DO NOT INSTALL IT ON YOUR WEBSITE.

A chinese person (in our contact case was AMELIA SMITH (amelia.smith12@outlook.com) is sending emails from outlook dot com saying they'd pay $50 to $100 per month if you install that. It has a backdoor that lets people upload and delete files from your server.

It is not the plugin https://github.com/sketchmouse/wp-gif-player that @dbedenknecht created, since that one (original) doesn't have the sneaky file in question, wp-inc.php

This "Amelia" is claiming to "verify" the plugin is installed in other sites by mentioning a different file, part of the original plugin.

Again, always check with a programmer before manually installing plugins into WordPress that aren't from wp.com

:)

*: note to programmers, I do know it's not a virus technically, but the people googling this won't probably know the difference. And it harms their websites.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment