The site that infected you looked completely normal. That was the point
Nearly 2,000 hacked WordPress sites were quietly turned into a delivery service for malware that copies crypto wallet files and, in some cases, locks the whole machine. None of them looked suspicious, because none of them were built to be.
A campaign researchers call StopAndProtect took over close to 2,000 WordPress websites — the ordinary kind: small shops, blogs, local businesses, portfolio pages. The owners did nothing wrong on purpose. Their sites just kept running, looking exactly as before, while serving visitors something extra.
According to Decrypt's report on the campaign, that something extra did three jobs: install malware, hunt for crypto wallet files on the computer, and in some cases drop ransomware — the software that encrypts everything you own on the drive and asks for money. One break-in, three ways to get paid.
Here's the part most people get wrong about getting hacked. Almost nobody is infected on a shady corner of the internet. They're infected on a page that looks like a page they've seen a hundred times, because someone else's website was broken into and quietly repurposed. WordPress runs a huge share of the web — the small-business, one-person, set-it-and-forget-it share. That's exactly the share nobody updates.
Two thousand hacked sites is not two thousand victims. It's two thousand doors.
And the crypto part is simpler than it sounds. If you keep coins in an app or a browser extension on your laptop, your wallet lives on that machine as a file. Copy the file, get the password or a keylog, and the coins move — no exchange, no support line, no reversal. That's why wallet files are the first thing this kind of malware looks for: it's the only loot on your computer that turns into cash the same day.
Ransomware on top is the fallback. If you had nothing worth stealing, they lock your files and sell them back to you. The economics are brutal but obvious: once you've paid for the break-in, you might as well try every way to monetise it.
Two groups, and they're rarely the same people. First: anyone whose crypto sits in an app or browser extension on the same laptop they use for everything else — which is most people under 35 with their first couple of thousand in coins. A hardware wallet feels like an overpriced USB stick right up to the day it's the only reason you still have money. Second: anyone who runs a WordPress site — freelancers with a portfolio page, small shops, a side project that's been online since 2019 with plugins nobody has touched since. If your site is one of the 2,000, you're not the target. You're the weapon, and your visitors are the target.
Watch for the entry point to be named. Campaigns like this almost always run through one outdated plugin or theme, and once security researchers publish which one, the fix becomes a five-minute job for site owners — and the infection count usually jumps, because scanning finds sites nobody had counted. The second thing to watch: whether the number stays near 2,000 in the next update or climbs. And on the crypto side, whether any of the stolen wallets show up being drained in bulk on-chain — that's when we'll know how much this actually earned.
The uncomfortable part isn't the malware. It's that the internet's soft underbelly is thousands of small sites run by people who have no idea they're running infrastructure. A bakery's blog isn't a security perimeter — but it is one now.
Sources: Decrypt, «Nearly 2,000 Hacked WordPress Sites Turned Into Criminal Infrastructure»