Thousands of WordPress websites hacked via a plugin to steal user data

A new variant of the infamous ClearFake malware (AKA ClickFix) has been detected in the wild and has already managed to compromise thousands of WordPress websites.

GoDaddy researchers claim to have discovered a variant of this campaign, which installs malicious plugins on the website builder’s sites. The threat actors would use credentials stolen elsewhere (or purchased on the black market) to log into the website’s WordPress administrator account and install a seemingly benign plugin.