Source Defense Research Flags Risky Loader on 12K+ WordPress Sites

A suspicious JavaScript loader found on more than 12,000 WordPress sites shows why client-side security cannot depend only on known bad domains or confirmed final payloads. The impact is broad: thousands of ordinary websites may be unknowingly giving an attacker a browser-side foothold that can profile visitors, communicate with command-and-control infrastructure, and execute attacker-supplied JavaScript when instructed. No confirmed final-stage payload, such as card skimming, credential theft, redirect activity, or ClickFix instructions, has been observed yet. The risk is that the loader is already capable of becoming one. Source Defense Research Intelligence helps address this exact challenge by tracking evolving client-side attack patterns, validating risky signatures, and feeding that research into the Source Defense defense system so customers can identify threats, understand the risk, and take action even when the attacker rotates infrastructure or keeps the payload dormant.

Attack details

This is a first-party page injection that triggers attacker-controlled third-party script activity. The malicious logic is injected directly into WordPress pages as heavily obfuscated inline JavaScript, so it begins as first-party page content from the visitor’s perspective. Once running in the browser, the loader communicates with external command-and-control domains using encoded POST requests, including paths under a consistent /x9i32md/w1/* structure. The script checks for bots, crawlers, scanners, and automation indicators, attempts to remove its own script element from the DOM, creates or retrieves persistent identifiers, stores values in localStorage, collects the current page URL, and gathers a filtered set of browser and window properties. The most concerning behavior is its server-controlled execution path: after fetching and decoding a command-and-control response, the loader can parse the response and run returned JavaScript through eval(). It also exposes a browser-side control object and can attach click handlers to page elements, meaning the second-stage payload may only appear after a visitor clicks a meaningful button such as Login, Submit, Checkout, Pay, Donate, Continue, or Verify. That click-gated behavior helps explain why routine page-load scanning may see only short encoded responses while missing payloads that are selectively activated later.

How Source Defense protects you

Source Defense extends security into the browser, where this attack operates. For this campaign, the strongest detection point is the risky loader signature and the behavior surrounding it, not just the destination domain. The attacker can rotate command-and-control infrastructure, and newly registered domains may not appear in reputation feeds immediately. Source Defense Research Intelligence strengthens protection by studying live client-side threats, gathering and verifying risky signatures, and incorporating those findings into the Source Defense defense system as part of the ongoing service customers rely on. 

In this case, the injected loader would be flagged precisely because it contains a malware signature, sends data to a blacklisted domain when known infrastructure is involved, and executes a risky action, specifically eval(). 

These signals give security teams actionable visibility into browser-side risk even before a final payload is captured, helping them prioritize response and take action before dormant loader behavior becomes active data theft. If the attack does become active and begins accessing sensitive payment fields, additional behavior-based alerts would be triggered as well, including Accessing PCI data and Transferring data.

CSP and SRI are browser-enforced controls that can help with policy and integrity, but they can struggle when malicious code is injected inline, when trust relationships are broad, or when risky behavior is dynamic and command-controlled. WAFs and server-side monitoring protect the application environment, but they may not see what injected JavaScript does inside the visitor’s browser before data reaches the server. Source Defense provides browser-side runtime visibility and control over script behavior, including risky execution, unauthorized transfers, suspicious storage use, sensitive data access, and communication with known malicious infrastructure.

Key takeaways

This campaign reinforces a recurring lesson in client-side security: waiting for the final payload is too late. The unusual twist here is the scale and the detection method. More than 12,000 WordPress sites were found with a suspicious loader whose most actionable indicator is the code-level signature itself, not a confirmed skimmer or credential thief. The loader already gives the attacker a browser-side foothold, supports interaction-gated delivery, and can execute attacker-supplied JavaScript on demand. 

Domain blocklists, CSP, SRI, WAFs, and server-side logs each have value, but none of them alone provides the research-backed browser visibility needed to identify this kind of rotating, selectively activated JavaScript threat. Source Defense helps close that gap by combining client-side runtime monitoring with Research Intelligence that tracks evolving attacker techniques and turns verified risky signatures into practical defense giving customers the visibility they need to detect risk early and take action before sensitive data is exposed.

PCI DSS 4.0 makes client-side security a priority.

Source Defense delivers a solution for 6.4.3 and 11.6.1 without adding a burden to your security teams.

Source Defense
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.