WooCommerce Malware Incident Response
Budget: $40.0 - $70.0
HOURLY / PART_TIME
⭐ 0.00 (0)
United States
wordpress, woocommerce, php, wp-ecommerce
Qualifiche preferite
- Esperienza: Esperto
Our WooCommerce site on WordPress hosted by Pressable has a confirmed, active malware injection that returns after cleanup. We need an incident-response specialist to fully remediate the issue, identify how the attacker maintains access, and prevent recurrence. This is not a simple malware removal task. The freelancer should investigate the root cause, secure the site, and provide a clear report on the compromise, remediation steps, and next steps to protect the site long-term.
What's confirmed so far:
"ClickFix" / fake-CAPTCHA overlay injecting clipboard-hijacking JavaScript (confirmed present in served admin-page HTML — navigator.clipboard / atob in page source).
Injection appears to be gated to authenticated admin sessions — anonymous front-end and external scans read clean, which has masked it.
Payload has been found in multiple locations across incidents (theme functions.php in an inactive default theme; a database option in wp_options), suggesting deliberate, structured access rather than a single drive-by file.
A prior related incident referenced an unauthenticated PHP webshell and a second shell in wp-content/uploads/.
Site was recently migrated to Pressable (early Sept); infection may have arrived with the migration.
Hosting is Pressable (SSH/SFTP/WP-CLI available); Wordfence installed post-incident.
Scope of work:
Identify and remove the active admin-gated injection and confirm removal in served HTML.
Locate the persistence mechanism / backdoor — the reason cleanup doesn't hold (mu-plugins, cron, DB-stored loaders, rogue admin accounts, compromised credentials).
Determine the entry vector using host access logs (we can obtain Pressable logs).
Full remediation: credential rotation plan, admin-account audit, integrity check of core/plugins/themes.
Written report: what was found, how they got in, what was changed, and hardening recommendations to prevent recurrence.
Deliverables / milestones:
M1: Live injection identified + removed, verified clean in admin-session HTML.
M2: Persistence mechanism and entry vector documented.
M3: Full remediation complete + written incident report + hardening plan.
Apri su Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Accedi