← Live feed

WooCommerce Malware Incident Response

Budget: $40.0 - $70.0 HOURLY / PART_TIME ⭐ 0.00 (0) United States

wordpress, woocommerce, php, wp-ecommerce

Preferred qualifications

  • Experience: Expert
Our WooCommerce site on WordPress hosted by Pressable has a confirmed, active malware injection that returns after cleanup. We need an incident-response specialist to fully remediate the issue, identify how the attacker maintains access, and prevent recurrence. This is not a simple malware removal task. The freelancer should investigate the root cause, secure the site, and provide a clear report on the compromise, remediation steps, and next steps to protect the site long-term. What's confirmed so far: "ClickFix" / fake-CAPTCHA overlay injecting clipboard-hijacking JavaScript (confirmed present in served admin-page HTML — navigator.clipboard / atob in page source). Injection appears to be gated to authenticated admin sessions — anonymous front-end and external scans read clean, which has masked it. Payload has been found in multiple locations across incidents (theme functions.php in an inactive default theme; a database option in wp_options), suggesting deliberate, structured access rather than a single drive-by file. A prior related incident referenced an unauthenticated PHP webshell and a second shell in wp-content/uploads/. Site was recently migrated to Pressable (early Sept); infection may have arrived with the migration. Hosting is Pressable (SSH/SFTP/WP-CLI available); Wordfence installed post-incident. Scope of work: Identify and remove the active admin-gated injection and confirm removal in served HTML. Locate the persistence mechanism / backdoor — the reason cleanup doesn't hold (mu-plugins, cron, DB-stored loaders, rogue admin accounts, compromised credentials). Determine the entry vector using host access logs (we can obtain Pressable logs). Full remediation: credential rotation plan, admin-account audit, integrity check of core/plugins/themes. Written report: what was found, how they got in, what was changed, and hardening recommendations to prevent recurrence. Deliverables / milestones: M1: Live injection identified + removed, verified clean in admin-session HTML. M2: Persistence mechanism and entry vector documented. M3: Full remediation complete + written incident report + hardening plan.
Open job

AI proposal draft

Generate a short cover letter to copy into the offer. Says you are interested and ready to work.

Sign in to generate an AI proposal draft.

Log in