Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    This Week’s Awesome Tech Stories From Around the Web (Through October 3)

    October 3, 2026

    Muse Creates Detailed Profiles of All Your Friends and Family

    October 3, 2026

    AI Is Making a Mess of Nurses’ Schedules. They Say It’s a Safety Issue

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • This Week’s Awesome Tech Stories From Around the Web (Through October 3)
    • Muse Creates Detailed Profiles of All Your Friends and Family
    • AI Is Making a Mess of Nurses’ Schedules. They Say It’s a Safety Issue
    • Don’t be fooled—LLMs don’t reason
    • Computer Science Has Long Understood What It Takes to Keep AI Under Control
    • Trump’s Crazy AI Rebrand Was a Loyalty Test for Tech Execs—and It Worked
    • The Download: a biological de-aging contest and why LLMs don’t reason
    • These AI Experts Want to Do High-Stakes Research Out in the Open
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»WordPress malware campaign hides payloads in Steam profiles
    Cybersecurity

    WordPress malware campaign hides payloads in Steam profiles

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 1, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    WordPress malware campaign hides payloads in Steam profiles
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data.

    The threat actor used invisible Unicode characters to encode a payload that builds a URL to a malicious script. By leveraging Valve’s platform, the attacker avoids maintaining a separate C2 infrastructure and evades traditional detection methods.

    Since the campaign was first uncovered in July 2025, GoDaddy security engineers have found malware on approximately 1,980 WordPress websites.

    It is unclear how the hackers breach the websites, but researchers assess that the initial infection vector ranges from stolen admin logins or compromised FTP/SFTP credentials to the exploitation of a vulnerable WordPress theme or plugin, or a supply-chain compromise.

    The first-stage malware planted on a website uses WordPress page loads to reach specific Steam profiles and extract text from benign-looking comments.

    However, the text includes hidden Unicode characters that conceal malicious payloads sometimes disguised as ASCII art.

    Malicious Steam comment
    Source: GoDaddy

    GoDaddy researchers note in a report that the threat actor uses six invisible Unicode characters for the encoded payload:

    • Zero-width non-joiner (U+200C)
    • Zero-width joiner (U+200D)
    • Function application (U+2061)
    • Invisible times (U+2062)
    • Invisible separator (U+2063)
    • Invisible plus (U+2064)

    The decoder ignores any visible character and maps the invisible ones to a corresponding number; then it converts them to binary representation and reconstructs bytes from the binary stream.

    “This encoding allows binary data to be embedded within normal-looking text. The visible characters serve as camouflage while the invisible characters carry the actual payload,” GoDaddy says.

    According to the researchers, the decoded payload is used to build a hello-mywordl[.]info URL serving JavaScript code that is injected into every frontend WordPress page.

    Based on the file names (e.g., asahi-jquery-min-bundle and lodash.core.min.js), the retrieved malware is disguised as a legitimate JavaScript library.

    The final stage of the attack is implementing a backdoor that responds to specially crafted POST requests that include a specific authentication cookie. If the “tEcaKKXEsb cookie is present, the backdoor accepts base64-encoded PHP code via POST parameter,” the researchers explain.

    POST request with the right cookie
    Source: GoDaddy

    GoDaddy describes several evasion mechanisms employed by the malware, including obfuscated strings using octal and hex escapes, randomized function names, fake disabled logging code, and the use of standard WordPress APIs, allowing it to blend with normal activity.

    Site owners can defend by checking for references to Steam Community URLs, suspicious external JavaScript injections, outbound connections from WordPress servers to Steam, and unexpected scripts loading from domains such as hello-mywordl[.]info.

    Other indicators include invisible Unicode characters, suspicious _transient_caption_ cache entries, disabled SSL verification in cURL requests, and POST requests containing the malware’s authentication cookies or the new_code parameter.

    The researchers recommend that security teams prioritize restoring from a known good backup before the infection date. If this is not possible, the manual cleaning process should be thorough because “attackers can reinstall removed code through the backdoor if any component remains active.”

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now

    Campaign hides malware payloads profiles steam WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Muse Creates Detailed Profiles of All Your Friends and Family

    October 3, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • This Week’s Awesome Tech Stories From Around the Web (Through October 3)
    • Muse Creates Detailed Profiles of All Your Friends and Family
    • AI Is Making a Mess of Nurses’ Schedules. They Say It’s a Safety Issue
    • Don’t be fooled—LLMs don’t reason
    • Computer Science Has Long Understood What It Takes to Keep AI Under Control

    This Week’s Awesome Tech Stories From Around the Web (Through October 3)

    October 3, 2026

    Muse Creates Detailed Profiles of All Your Friends and Family

    October 3, 2026

    AI Is Making a Mess of Nurses’ Schedules. They Say It’s a Safety Issue

    October 3, 2026

    Don’t be fooled—LLMs don’t reason

    October 3, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.