Malicious threat actors exploited some of the vulnerabilities present on premium theme plugins available on WordPress, the content management system (CSM).
The over 17,000 sites fell victim to the Balada Injector, which was first uncovered by cybersecurity firm Dr. Web in December 2022. The primary goal of these attacks is to inject a Linux backdoor into compromised sites.
The backdoor then leads website visitors to fake tech support pages, fraudulent lottery claims, and push notification claims. According to BleepingComputer, attackers either scam the victims themselves or offer the services to other cybercriminals.
The Balada Injector targets the CVE-2023-3169 cross-site scripting (XSS) vulnerability present in the tagDiv Composer, a companion tool for tagDiv’s popular Newspaper and Newsmag themes for WordPress sites.
According to numbers from Envato, sales between the two plugins expose a potential 155,500 websites to the threat, not accounting for plugins that were pirated. Sucuri, a web security company, recently revealed that Balada Injector has been active since 2017, estimating that it has compromised nearly one million WordPress websites by April 2023.
“This is a particularly tricky breach, as the nature of the code used by Balada hackers can make it hard to detect. However, if you do administer a WordPress site that uses the themes Newspaper or Newsmag, there are a few telltale signs you can look out for,” said Jamie Akhtar, co-founder and CEO at CyberSmart.
Recommended reading
- Disgruntled Ex Employee Blamed For Popular WordPress Plugin Hack
- Network of Infected Androids Used for Fraudulent Activities
- Verizon Offloads Tumblr to WordPress Owner Automattic
“The Balada Hackers usually try a number of different routes to try and gain total control over your site and this leaves traces. Check for any strange redirects on pages, code you don’t recognise, or new admin accounts that someone in your organisation didn’t set up.”
To safeguard against Balada Injector attacks, experts recommend upgrading the tagDiv Composer plugin to version 4.2 or later, keeping all themes and plugins updated, removing dormant user accounts, and regularly scanning files for hidden backdoors.
“The recent tagDiv exploit joins many before it and will not be the last, whether by takeover of abandoned plugin projects or by directly attacking vulnerabilities in code, threat actors will continue to target your business online,” continued Akhtar.





